First published: Tue Aug 20 2019(Updated: )
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system. IBM X-Force ID: 164069.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Contract Management | >=10.1.0<=10.1.3 | |
IBM Emptoris Sourcing | >=10.1.0<=10.1.3 | |
IBM Emptoris Spend Analysis | >=10.1.0<=10.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-4485.
The severity level of CVE-2019-4485 is medium (4.3).
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 are affected by CVE-2019-4485.
CVE-2019-4485 exposes sensitive information that could be used in further attacks against the system.
Yes, IBM has released security advisories addressing CVE-2019-4485. Please refer to the IBM Support website for more information.