First published: Tue Aug 26 2014(Updated: )
Cross-site scripting (XSS) vulnerability in IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Sourcing Portfolio | =9.5.0.0 | |
IBM Emptoris Sourcing Portfolio | =9.5.0.1 | |
IBM Emptoris Sourcing Portfolio | =9.5.0.2 | |
IBM Emptoris Sourcing Portfolio | =9.5.1.0 | |
IBM Emptoris Sourcing Portfolio | =9.5.1.1 | |
IBM Emptoris Sourcing Portfolio | =9.5.1.2 | |
IBM Emptoris Sourcing Portfolio | =10.0.0.0 | |
IBM Emptoris Sourcing Portfolio | =10.0.1.0 | |
IBM Emptoris Sourcing Portfolio | =10.0.1.1 | |
IBM Emptoris Sourcing Portfolio | =10.0.1.2 | |
IBM Emptoris Sourcing Portfolio | =10.0.2.0 | |
IBM Emptoris Sourcing Portfolio | =10.0.2.2 | |
IBM Emptoris Sourcing Portfolio | =10.0.2.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3033 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To address CVE-2014-3033, you should upgrade to IBM Emptoris Sourcing Portfolio versions 9.5.1.3, 10.0.0.1, 10.0.1.3, or 10.0.2.4 or later.
CVE-2014-3033 affects versions of IBM Emptoris Sourcing Portfolio prior to the specified fix releases.
CVE-2014-3033 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Yes, CVE-2014-3033 can be exploited by remote authenticated users through a crafted URL.