First published: Thu Feb 20 2020(Updated: )
IBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 173348.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Spend Analysis | >=10.1.0.0<10.1.0.34 | |
IBM Emptoris Spend Analysis | >=10.1.1.0<10.1.1.33 | |
IBM Emptoris Spend Analysis | >=10.1.3.0<10.1.3.29 | |
IBM Emptoris Strategic Supply Management Platform | >=10.1.0.0<10.1.0.34 | |
IBM Emptoris Strategic Supply Management Platform | >=10.1.1.0<10.1.1.33 | |
IBM Emptoris Strategic Supply Management Platform | >=10.1.3.0<10.1.3.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-4752 is high with a CVSS base score of 8.8.
If you are using IBM Emptoris Spend Analysis or IBM Emptoris Strategic Supply Management Platform versions between 10.1.0.0 and 10.1.0.34, 10.1.1.0 and 10.1.1.33, or 10.1.3.0 and 10.1.3.29, your system is affected by CVE-2019-4752.
SQL injection is a vulnerability that allows an attacker to manipulate SQL statements to execute arbitrary commands or view, modify, or delete data in a database.
An attacker can exploit CVE-2019-4752 by sending specially-crafted SQL statements to the vulnerable IBM Emptoris platforms, allowing the attacker to perform unauthorized actions such as viewing, adding, modifying, or deleting information in the back-end database.
To fix CVE-2019-4752, IBM recommends upgrading to a fixed version of IBM Emptoris Spend Analysis or IBM Emptoris Strategic Supply Management Platform. Please refer to the IBM support pages for specific version information and upgrade instructions.