← Back to CVE List

CVE-2020-4895

Published: 2021-01-07T18:15Z
Last Modified: 2024-11-21T05:33Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
IBM Emptoris Strategic Supply Management 10.1.0, 10.1.1, and 10.1.3 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190986. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt