CVE-2020-4893
5.9MEDIUM
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 7 January 2021
Summary
IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to information disclosure via man in the middle methods. IBM X-Force ID: 190984.
Affected Version(s)
Emptoris Strategic Supply Management 10.1.0
Emptoris Strategic Supply Management 10.1.1
Emptoris Strategic Supply Management 10.1.3
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved