First published: Thu Jan 07 2021(Updated: )
IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 is vulnerable to web cache poisoning, caused by improper input validation by modifying HTTP request headers. IBM X-Force ID: 190987.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Sourcing | >=10.1.0.0<10.1.0.38 | |
IBM Emptoris Sourcing | >=10.1.1.0<10.1.1.35 | |
IBM Emptoris Sourcing | >=10.1.3.0<10.1.3.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-4896 is medium (6.5).
CVE-2020-4896 is a vulnerability in IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3 that allows web cache poisoning through improper input validation by modifying HTTP request headers.
The affected software for CVE-2020-4896 is IBM Emptoris Sourcing 10.1.0, 10.1.1, and 10.1.3.
To fix CVE-2020-4896, upgrade to a version higher than 10.1.0.38 for IBM Emptoris Sourcing 10.1.0, higher than 10.1.1.35 for IBM Emptoris Sourcing 10.1.1, or higher than 10.1.3.30 for IBM Emptoris Sourcing 10.1.3.
Yes, you can find more information about CVE-2020-4896 on the IBM X-Force ID: 190987 page and the IBM support page.