First published: Thu Jan 07 2021(Updated: )
IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190986.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Strategic Supply Management | >=10.1.0.0<10.1.0.38 | |
IBM Emptoris Strategic Supply Management | >=10.1.1.0<10.1.1.35 | |
IBM Emptoris Strategic Supply Management | >=10.1.3.0<10.1.3.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-4895.
CVE-2020-4895 has a severity level of medium.
The affected software for CVE-2020-4895 is IBM Emptoris Strategic Supply Management version 10.1.0, 10.1.1, and 10.1.3.
CVE-2020-4895 allows users to embed arbitrary JavaScript code in the Web UI, potentially leading to credentials disclosure within a trusted system.
Yes, you can find more information about CVE-2020-4895 on the IBM X-Force Exchange and IBM Support pages.