PT-2021-12217 · Ibm · Ibm Emptoris Strategic Supply Management
Published
2021-01-07
·
Updated
2021-01-08
·
CVE-2020-4893
CVSS v3.1
5.9
Medium
| Vector | I:N/S:U/C:H/UI:N/AV:N/A:N/PR:N/AC:H |
Name of the Vulnerable Software and Affected Versions
IBM Emptoris Strategic Supply Management versions 10.1.0 through 10.1.3
Description
The issue allows sensitive information to be transmitted in HTTP GET request parameters, potentially leading to information disclosure via man-in-the-middle methods.
Recommendations
For versions 10.1.0 through 10.1.3, consider restricting the use of HTTP GET requests for sensitive information until a patch is available. As a temporary workaround, avoid using sensitive parameters in HTTP GET requests to minimize the risk of exploitation.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Emptoris Strategic Supply Management