CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable. It involves a SQL injection risk.
CVE
CVE-2019-4481
Severity
CRITICAL
CVSS
9.8
EPSS
1.96%
Original NVD Description
IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 164064.
Related CVEs
Other vulnerabilities affecting the same vendor(s)