First published: Tue Aug 20 2019(Updated: )
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 164067.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Contract Management | >=10.1.0<=10.1.3 | |
IBM Emptoris Spend Analysis | >=10.1.0<=10.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-4483 is a vulnerability in IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 that allows remote attackers to perform SQL injection and manipulate the backend database.
CVE-2019-4483 has a severity rating of 9.8 (Critical).
The affected software for CVE-2019-4483 includes IBM Contract Management versions 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis versions 10.1.0 through 10.1.3.
A remote attacker can exploit CVE-2019-4483 by sending specially-crafted SQL statements to perform unauthorized actions on the backend database.
More information about CVE-2019-4483 can be found at the IBM X-Force Exchange (https://exchange.xforce.ibmcloud.com/vulnerabilities/164067) and the IBM support website (https://www.ibm.com/support/docview.wss?uid=ibm10880223).