CVE-2016-5953
01.02.2017, 22:59
IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.Enginsight
Vendor | Product | Version |
---|---|---|
ibm | sterling_selling_and_fulfillment_foundation | 9.1.0 |
ibm | sterling_selling_and_fulfillment_foundation | 9.2.0 |
ibm | sterling_selling_and_fulfillment_foundation | 9.2.1 |
ibm | sterling_selling_and_fulfillment_foundation | 9.3 |
ibm | sterling_selling_and_fulfillment_foundation | 9.4 |
ibm | sterling_selling_and_fulfillment_foundation | 9.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration