Description
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 could allow an authenticated user to obtain sensitive information from error messages IBM X-Force ID: 161034.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://www.ibm.com/support/docview.wss?uid=ibm10880221
VDB Entry, Vendor Advisory vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/161034
Scores
CVSS v3
4.3
EPSS
0.0099
EPSS Percentile
58.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-209
Status
published
Products (3)
ibm/emptoris_contract_management
10.1.0 - 10.1.3
ibm/emptoris_sourcing
10.1.0 - 10.1.3
ibm/emptoris_spend_analysis
10.1.0 - 10.1.3
Published
Aug 20, 2019
Tracked Since
Feb 18, 2026