First published: Tue Aug 13 2019(Updated: )
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 could allow an authenticated user to obtain sensitive information from error messages IBM X-Force ID: 161034.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Contract Management | >=10.1.0<=10.1.3 | |
IBM Emptoris Sourcing | >=10.1.0<=10.1.3 | |
IBM Emptoris Spend Analysis | >=10.1.0<=10.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this security issue is CVE-2019-4308.
The severity of CVE-2019-4308 is medium with a severity value of 4.3.
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 are affected by CVE-2019-4308.
An authenticated user can exploit CVE-2019-4308 to obtain sensitive information from error messages.
Yes, you can find additional references for CVE-2019-4308 at the following links: - [IBM X-Force ID: 161034](https://exchange.xforce.ibmcloud.com/vulnerabilities/161034) - [IBM Support Document](https://www.ibm.com/support/docview.wss?uid=ibm10880221)