CVE-2015-7398

Cross-site scripting (XSS) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
ibmCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 38%
VendorProductVersion
ibmemptoris_contract_management
9.5.0.0
ibmemptoris_contract_management
9.5.0.1
ibmemptoris_contract_management
9.5.0.2
ibmemptoris_contract_management
9.5.0.3
ibmemptoris_contract_management
9.5.0.4
ibmemptoris_contract_management
9.5.0.5
ibmemptoris_contract_management
9.5.0.6
ibmemptoris_contract_management
10.0.0.0
ibmemptoris_contract_management
10.0.0.1
ibmemptoris_contract_management
10.0.1.0
ibmemptoris_contract_management
10.0.1.1
ibmemptoris_contract_management
10.0.1.2
ibmemptoris_contract_management
10.0.1.3
ibmemptoris_contract_management
10.0.1.4
ibmemptoris_contract_management
10.0.1.5
ibmemptoris_contract_management
10.0.2.0
ibmemptoris_contract_management
10.0.2.1
ibmemptoris_contract_management
10.0.2.2
ibmemptoris_contract_management
10.0.2.3
ibmemptoris_contract_management
10.0.2.4
ibmemptoris_contract_management
10.0.2.5
ibmemptoris_contract_management
10.0.2.6
ibmemptoris_contract_management
10.0.2.7
ibmemptoris_contract_management
10.0.4.0
𝑥
= Vulnerable software versions