Information Disclosure Vulnerability in IBM Emptoris Supply Management Platform
CVE-2016-6029

5.9MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
14 August 2017

Summary

The IBM Emptoris Strategic Supply Management Platform versions 10.0 and 10.1 are susceptible to a vulnerability that allows remote attackers to access sensitive information. This security gap arises from the failure to adequately enable HTTP Strict Transport Security (HSTS). By exploiting this vulnerability, attackers can employ man-in-the-middle techniques to intercept and decipher confidential data transmitted over insecure connections. Organizations using these versions should implement mitigation strategies to safeguard sensitive data from potential interception.

Affected Version(s)

Emptoris Strategic Supply Management 10.0.0.0

Emptoris Strategic Supply Management 10.0.1.0

Emptoris Strategic Supply Management 10.0.2.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.