Vulnerabilities > IBM > Emptoris Contract Management > 10.1.0

DATE CVE VULNERABILITY TITLE RISK
2019-08-20 CVE-2019-4485 Information Exposure Through an Error Message vulnerability in IBM products
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system.
network
low complexity
ibm CWE-209
4.3
2019-08-20 CVE-2019-4484 Information Exposure Through an Error Message vulnerability in IBM products
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 generates an error message that includes sensitive information that could be used in further attacks against the system.
network
low complexity
ibm CWE-209
4.3
2019-08-20 CVE-2019-4483 SQL Injection vulnerability in IBM products
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8
2019-08-20 CVE-2019-4481 SQL Injection vulnerability in IBM products
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection.
network
low complexity
ibm CWE-89
critical
9.8
2019-08-20 CVE-2019-4308 Information Exposure Through an Error Message vulnerability in IBM products
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 could allow an authenticated user to obtain sensitive information from error messages IBM X-Force ID: 161034.
network
low complexity
ibm CWE-209
4.3
2019-04-29 CVE-2018-1961 Information Exposure vulnerability in IBM Emptoris Contract Management
IBM Emptoris Contract Management 10.0.0 and 10.1.3.0 could disclose sensitive information from detailed information from error messages.
network
low complexity
ibm CWE-200
5.3