Severity
5.9MEDIUM
EPSS
0.1%
top 67.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 7
Latest updateMay 24

Description

IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 transmits sensitive information in HTTP GET request parameters. This may lead to information disclosure via man in the middle methods. IBM X-Force ID: 190984.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDibm/emptoris_strategic_supply_management10.1.0.010.1.0.38+2
CVEListV5ibm/emptoris_strategic_supply_management10.1.0, 10.1.1, 10.1.3+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jf7p-v9hx-5vrc: IBM Emptoris Strategic Supply Management 102022-05-24
CVEList
CVE-2020-4893: IBM Emptoris Strategic Supply Management 102021-01-07

📋Vendor Advisories

1
Juniper
CVE-2020-1632: In a certain condition, receipt of a specific BGP UPDATE message might cause Juniper Networks Junos OS and Junos OS Evolved devices to advertise an in2020-04-15
CVE-2020-4893 (MEDIUM CVSS 5.9) | IBM Emptoris Strategic Supply Manag | cvebase.io