First published: Thu Jan 07 2021(Updated: )
IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190988.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Emptoris Contract Management | >=10.1.0.0<10.1.0.38 | |
IBM Emptoris Contract Management | >=10.1.1.0<10.1.1.35 | |
IBM Emptoris Contract Management | >=10.1.3.0<10.1.3.30 | |
IBM Emptoris Spend Analysis | >=10.1.0.0<10.1.0.38 | |
IBM Emptoris Spend Analysis | >=10.1.1.0<10.1.1.35 | |
IBM Emptoris Spend Analysis | >=10.1.3.0<10.1.3.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-4897.
CVE-2020-4897 has a severity level of medium with a severity value of 5.3.
IBM Emptoris Contract Management and IBM Emptoris Spend Analysis versions 10.1.0, 10.1.1, and 10.1.3 are affected by this vulnerability.
A remote attacker can exploit CVE-2020-4897 by obtaining sensitive information through a detailed technical error message returned in the browser.
Yes, here are some reference links for CVE-2020-4897: 1. [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/190988) 2. [IBM Support Page](https://www.ibm.com/support/pages/node/6398276) 3. [IBM Support Page](https://www.ibm.com/support/pages/node/6398280)