Emptoris Services Procurement
Vendor:
First CVE: Aug 30, 2017 · Active for 8 years
4
Total CVEs
More Total CVEs than 75% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 49% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Emptoris Services Procurement over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2017
8 years ago
Most Recent CVE
Aug 30, 2017
3,253 days ago
CVE Severity & Scoring
Emptoris Services Procurement4 CVEs
50%
50%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (25.0%)
Network3 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (50.0%)
Unknown0 (0.0%)
Required2 (50.0%)
Privileges Required
Low2 (50.0%)
High0 (0.0%)
None2 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1440HIGH IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a malicious fil | Aug 30, 2017 | 8.8 | 26 | NO | NO |
CVE-2017-1442HIGH IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from | Aug 30, 2017 | 8.8 | 25 | NO | NO |
CVE-2017-1443MEDIUM IBM Emptoris Services Procurement 10.0.0.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the | Aug 30, 2017 | 6.1 | 20 | NO | NO |
CVE-2017-1441MEDIUM IBM Emptoris Services Procurement 10.0.0.5 could allow a local user to view sensitive information stored locally due to improper access control. IBM X-Force ID: 128106. | Aug 30, 2017 | 5.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (4 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (4 CVEs).
Media Mentions
Signals from CVEs in this product scope (4 CVEs).
Top CNAs Publishing CVEs For Emptoris Services Procurement
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 10.1.1.0 | 4 | 7.3 | 1.2% | 0 | 0 |
| 10.0.0.5 | 4 | 7.3 | 1.2% | 0 | 0 |
| 10.0.0.4 | 4 | 7.3 | 1.2% | 0 | 0 |
| 10.0.0.3 | 4 | 7.3 | 1.2% | 0 | 0 |
| 10.0.0.2 | 4 | 7.3 | 1.2% | 0 | 0 |
| 10.0.0.1 | 4 | 7.3 | 1.2% | 0 | 0 |
| 10.0.0.0 | 4 | 7.3 | 1.2% | 0 | 0 |