Vulnerability Bulletins

IBM Security Bulletin: Multiple vulnerabilities in IBM Emptoris Contract Management (CVE-2015-5050, CVE-2015-5042, CVE-2015-7398)

   
Affected software IBM
 
IBM Emptoris Contract Management is vulnerable to cross-site request scripting and forgery attacks due to flaw in handling of untrusted user input. In addition, IBM Emptoris Contract Management could allow a remote attacker to include arbitrary files. CVE(s): CVE-2015-5050, CVE-2015-5042 and CVE-2015-7398Affected product(s) and affected version(s):IBM Emptoris Contract Management 9.5.0.x, 10.0.0.x, 10.0.1.x, 10.0.2.x, 10.0.4 versions Refer to the following reference URLs for remediation and

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_multiple_vulnerabilities_in_ibm_emptoris_contract_management_cve_2015_5050_cve_2015_5042_cve_2015_7398?lang=en_us