Vulnerability Bulletins

IBM Security Bulletin: Information disclosure vulnerability reported in IBM Emptoris Sourcing (CVE-2015-5024)

   
Affected software IBM
 
IBM Emptoris Sourcing could allow an authenticated user to view other users bids which could contain sensitive information that they should not have access to. This vulnerability is limited to the supplier bid report. CVE(s): CVE-2015-5024 Affected product(s) and affected version(s): IBM Emptoris Sourcing 10.0.2.0 through 10.0.4.0 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin:

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_information_disclosure_vulnerability_reported_in_ibm_emptoris_sourcing_cve_2015_5024?lang=en_us