CVE-2014-6212: IBM Emptoris
Medium severity, CVSS 4.0. EPSS: 1.4% chance of exploitation in the next 30 days.
The Echo API in IBM Emptoris Contract Management 9.5.x before 9.5.0.6 iFix11, 10.0.0.x before 10.0.0.1 iFix12, 10.0.1.x before 10.0.1.5 iFix2, and 10.0.2.x before 10.0.2.2 iFix5; Emptoris Sourcing 9.5 before 9.5.1.3 iFix2, 10.0.0.x before 10.0.0.1 iFix1, 10.0.1.x before 10.0.1.3 iFix1, and 10.0.2.x before 10.0.2.5; and Emptoris Program Management (aka PGM) and Strategic Supply Management (aka SSMP) 10.0.0.x before 10.0.0.3 iFix6, 10.0.1.x before 10.0.1.4 iFix1, and 10.0.2.x before 10.0.2.5 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Affected products
- IBM Emptoris: version strategic_supply_management only
- IBM Emptoris Contract Management: version 9.5.0.0 only; version 9.5.0.1 only; version 9.5.0.2 only; version 9.5.0.3 only; version 9.5.0.4 only; version 9.5.0.5 only; …
- IBM Emptoris Program Management: version 10.0.0.0 only; version 10.0.0.1 only; version 10.0.0.2 only; version 10.0.0.3 only; version 10.0.1.0 only; version 10.0.1.1 only; …
- IBM Emptoris Sourcing Portfolio: version 9.5.0.0 only; version 9.5.0.1 only; version 9.5.0.2 only; version 9.5.1.0 only; version 9.5.1.1 only; version 9.5.1.2 only; …
Published 2015-01-10. Last modified 2026-06-17.