Vulnerability Description
IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNet P8 systems with IBM Content Search Services, which allows local users to bypass intended document-access restrictions and obtain sensitive information via a crafted search query.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Content Collector | 3.0.0.0 |
Related Weaknesses (CWE)
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21696594PatchVendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21696594PatchVendor Advisory
FAQ
What is CVE-2015-0146?
CVE-2015-0146 is a vulnerability with a CVSS score of 2.1 (LOW). IBM Content Collector for Email 3.0 before 3.0.0.6-IBM-ICC-Server-IF001 and 4.0 before 4.0.0.3-IBM-ICC-Server-IF001 does not properly handle an unspecified query operator during searches of IBM FileNe...
How severe is CVE-2015-0146?
CVE-2015-0146 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-0146?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Content Collector.