CVE-2020-4897
07.01.2021, 18:15
IBM Emptoris Contract Management and IBM Emptoris Spend Analysis 10.1.0, 10.1.1, and 10.1.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 190988.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | emptoris_contract_management | 10.1.0.0 ≤ 𝑥 < 10.1.0.38 |
ibm | emptoris_contract_management | 10.1.1.0 ≤ 𝑥 < 10.1.1.35 |
ibm | emptoris_contract_management | 10.1.3.0 ≤ 𝑥 < 10.1.3.30 |
ibm | emptoris_spend_analysis | 10.1.0.0 ≤ 𝑥 < 10.1.0.38 |
ibm | emptoris_spend_analysis | 10.1.1.0 ≤ 𝑥 < 10.1.1.35 |
ibm | emptoris_spend_analysis | 10.1.3.0 ≤ 𝑥 < 10.1.3.30 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References