Information Disclosure Vulnerability in IBM Emptoris Supply Management Platform
CVE-2016-6029
5.9MEDIUM
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 14 August 2017
What is CVE-2016-6029?
The IBM Emptoris Strategic Supply Management Platform versions 10.0 and 10.1 are susceptible to a vulnerability that allows remote attackers to access sensitive information. This security gap arises from the failure to adequately enable HTTP Strict Transport Security (HSTS). By exploiting this vulnerability, attackers can employ man-in-the-middle techniques to intercept and decipher confidential data transmitted over insecure connections. Organizations using these versions should implement mitigation strategies to safeguard sensitive data from potential interception.
Affected Version(s)
Emptoris Strategic Supply Management 10.0.0.0
Emptoris Strategic Supply Management 10.0.1.0
Emptoris Strategic Supply Management 10.0.2.0