IBM Emptoris Contract Management product reveals detailed error messages in
certain features that might be vulnerable to attacks.
CVEID: [CVE-2018-1961](http://cve.mitre.org/cgi-
bin/cvename.cgi?name=CVE-2018-1961)
DESCRIPTION: IBM Emptoris Contract Management could disclose sensitive
information from detailed information from error messages.
CVSS Base Score: 5.3
CVSS Temporal Score: See
https://exchange.xforce.ibmcloud.com/vulnerabilities/153657
for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
IBM Emptoris Contract Management 10.0.x through 10.1.3.x
The remediation to this issue is to apply a fixpack(FP) / InterimFix(iFix) as
soon as practical. Please see below for the information on the fixes
available.
IBM Emptoris Contract Management
Versions affected
|
Remediation
Fixpack(FP) / InterimFix(iFix)
—|—
10.0.0.x | iFix 10.0.0.1
iFix20
or later
10.0.1.x
| iFix 10.0.1.5
iFix12
or later
10.0.2.x
| FP
10.0.2.21
or later
10.0.4.x
| iFix 10.0.4
iFix18
or later
10.1.0
| FP
10.1.0.24
or later
10.1.1
| FP
10.1.1.22
or later
10.1.3 | FP
10.1.3.15
or later
None
Subscribe to My Notifications to be notified of important
product support alerts like this.
Complete CVSS v3 Guide
On-line Calculator v3
Off
[IBM Secure Engineering Web Portal](http://www.ibm.com/security/secure-
engineering/bulletins.html)
IBM Product Security Incident Response Blog
13 December 2018: Original Version Published
*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.
According to the Forum of Incident Response and Security Teams (FIRST), the
Common Vulnerability Scoring System (CVSS) is an “industry open standard
designed to convey vulnerability severity and help to determine urgency and
priority of response.” IBM PROVIDES THE CVSS SCORES ““AS IS”” WITHOUT WARRANTY
OF ANY KIND, INCLUDING THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
FOR A PARTICULAR PURPOSE. CUSTOMERS ARE RESPONSIBLE FOR ASSESSING THE IMPACT
OF ANY ACTUAL OR POTENTIAL SECURITY VULNERABILITY.
[{“Product”:{“code”:“SSYQ89”,“label”:“Emptoris Contract Management”},“Business
Unit”:{“code”:“BU059”,“label”:“IBM Software w/o
TPS”},“Component”:“–”,“Platform”:[{“code”:“PF025”,“label”:“Platform
Independent”}],“Version”:“Version Independent”,“Edition”:“”,“Line of
Business”:{“code”:“LOB02”,“label”:“AI Applications”}}]