← Back

CVE-2019-4752

nvd nist
Published: Feb 20, 2020Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

IBM Emptoris Spend Analysis and IBM Emptoris Strategic Supply Management Platform 10.1.0.x, 10.1.1.x, and 10.1.3.x is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 173348.

Affected (6)

2 products
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
From 10.1.0.0 to 10.1.0.34
From 10.1.1.0 to 10.1.1.33
From 10.1.3.0 to 10.1.3.29
Ibm
From 10.1.0.0 to 10.1.0.34
From 10.1.1.0 to 10.1.1.33
From 10.1.3.0 to 10.1.3.29

References (6)

Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: psirt@us.ibm.com
Vendor Advisory
Source: psirt@us.ibm.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.