IBM Security Bulletin: Detailed error messages in IBM Emptoris Contract Management are vulnerable to attacks (CVE-2016-6018)

IBM Emptoris Contract Management product reveals detailed error messages in certain features that might be vulnerable to attacks.

CVE(s): CVE-2016-6018

Affected product(s) and affected version(s):

IBM Emptoris Contract Management 10.0.x through 10.1.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2uyFqOj
X-Force Database: http://ift.tt/2vxUFEg

The post IBM Security Bulletin: Detailed error messages in IBM Emptoris Contract Management are vulnerable to attacks (CVE-2016-6018) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2uyFihK