CVE-2014-4790
Summary
| CVE | CVE-2014-4790 |
|---|---|
| State | PUBLISHED |
| Assigner | ibm |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-08-26 10:55:04 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | IBM Emptoris Sourcing Portfolio 9.5.x before 9.5.1.3, 10.0.0.x before 10.0.0.1, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 and Emptoris Spend Analysis 9.5.x before 9.5.0.4, 10.0.1.x before 10.0.1.3, and 10.0.2.x before 10.0.2.4 do not properly restrict use of FRAME elements, which allows remote authenticated users to conduct phishing attacks, and bypass intended access restrictions or obtain sensitive information, via a crafted web site, related to a "frame injection" issue. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Emptoris Sourcing Portfolio | 10.0.0.0 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 10.0.1.0 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 10.0.1.1 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 10.0.1.2 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 10.0.2.0 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 10.0.2.2 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 10.0.2.3 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 9.5.0.0 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 9.5.0.1 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 9.5.0.2 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 9.5.1.0 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 9.5.1.1 | All | All | All |
| Application | Ibm | Emptoris Sourcing Portfolio | 9.5.1.2 | All | All | All |
| Application | Ibm | Emptoris Spend Analysis | 10.0.1.0 | All | All | All |
| Application | Ibm | Emptoris Spend Analysis | 10.0.1.1 | All | All | All |
| Application | Ibm | Emptoris Spend Analysis | 10.0.1.2 | All | All | All |
| Application | Ibm | Emptoris Spend Analysis | 10.0.2.0 | All | All | All |
| Application | Ibm | Emptoris Spend Analysis | 10.0.2.2 | All | All | All |
| Application | Ibm | Emptoris Spend Analysis | 9.5.0.0 | All | All | All |
| Application | Ibm | Emptoris Spend Analysis | 9.5.0.1 | All | All | All |
| Application | Ibm | Emptoris Spend Analysis | 9.5.0.2 | All | All | All |
| Application | Ibm | Emptoris Spend Analysis | 9.5.0.3 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory SA60481 - IBM Emptoris Sourcing Multiple Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-01.ibm.com | Patch, Vendor Advisory |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.