AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-4481

CRITICAL · CVSS 9.8 EPSS 1.96%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-08-20 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable. It involves a SQL injection risk.

CVE
CVE-2019-4481
Severity
CRITICAL
CVSS
9.8
EPSS
1.96%

Original NVD Description

IBM Contract Management 10.1.0 through 10.1.3 and IBM Emptoris Spend Analysis 10.1.0 through 10.1.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 164064.

Related CVEs

Other vulnerabilities affecting the same vendor(s)