CVE-2015-0146

IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.
References
Link Resource
http://www-01.ibm.com/support/docview.wss?uid=swg21696594 Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:content_collector:3.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_collector:3.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_collector:3.0.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_collector:3.0.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_collector:3.0.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_collector:3.0.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_collector:4.0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_collector:4.0.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:content_collector:4.0.0.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2015-03-18 10:59

Updated : 2024-02-28 12:20


NVD link : CVE-2015-0146

Mitre link : CVE-2015-0146

CVE.ORG link : CVE-2015-0146


JSON object : View

Products Affected

ibm

  • content_collector
CWE
CWE-264

Permissions, Privileges, and Access Controls