CVE-2019-4308: IBM Emptoris Contract Management
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
IBM Emptoris Sourcing 10.1.0 through 10.1.3, IBM Contract Management 10.1.0 through 10.1.3, and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 could allow an authenticated user to obtain sensitive information from error messages IBM X-Force ID: 161034.
Affected products
- IBM Emptoris Contract Management: from 10.1.0, up to and including 10.1.3
- IBM Emptoris Sourcing: from 10.1.0, up to and including 10.1.3
- IBM Emptoris Spend Analysis: from 10.1.0, up to and including 10.1.3
Published 2019-08-20. Last modified 2026-06-17.