First published: Thu Jan 07 2021(Updated: )
IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to information disclosure via man in the middle methods. IBM X-Force ID: 190984.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Strategic Supply Management | >=10.1.0.0<10.1.0.38 | |
IBM Emptoris Strategic Supply Management | >=10.1.1.0<10.1.1.35 | |
IBM Emptoris Strategic Supply Management | >=10.1.3.0<10.1.3.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-4893.
The severity of CVE-2020-4893 is medium with a severity value of 5.9.
CVE-2020-4893 allows the transmission of sensitive information in HTTP GET request parameters, which can lead to information disclosure via man-in-the-middle methods in IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3.
If you are using IBM Emptoris Strategic Supply Management versions 10.1.0 to 10.1.0.38, 10.1.1 to 10.1.1.35, or 10.1.3 to 10.1.3.30, your system may be affected by CVE-2020-4893.
IBM has released fixpacks to address the vulnerability. Please refer to the IBM support page for the specific fixpacks applicable to your version of IBM Emptoris Strategic Supply Management.