First published: Tue Aug 20 2019(Updated: )
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164068.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Contract Management | >=10.1.0<=10.1.3 | |
IBM Emptoris Sourcing | >=10.1.0<=10.1.3 | |
IBM Emptoris Spend Analysis | >=10.1.0<=10.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-4484.
The severity of CVE-2019-4484 is medium with a severity value of 4.3.
IBM Emptoris Sourcing, IBM Contract Management, and IBM Emptoris Spend Analysis versions 10.1.0 through 10.1.3 are affected.
This vulnerability allows attackers to obtain sensitive information, which can be used in further attacks against the system.
Apply the necessary patches or updates provided by IBM to secure the affected products.