CVE-2013-0578

The Sterling Order Management APIs in IBM Sterling Multi-Channel Fulfillment Solution 8.0 before HF128 and IBM Sterling Selling and Fulfillment Foundation 8.5 before HF93, 9.0 before HF73, 9.1.0 before FP45, and 9.2.0 before FP17, when the API tester is enabled, do not require administrative credentials, which allows remote authenticated users to obtain sensitive database information via a request to the API tester URI.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ibm:sterling_multi-channel_fulfillment_solution:8.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:8.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.16:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.12:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.14:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0.10:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.14:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.15:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.23:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.24:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.31:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.32:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.39:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.40:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.11:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.18:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.19:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.20:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.27:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.28:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.35:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.36:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.44:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.12:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.13:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.21:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.22:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.29:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.30:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.37:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.38:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.9:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.16:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.17:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.25:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.26:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.33:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.34:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.41:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.42:*:*:*:*:*:*:*
cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0.43:*:*:*:*:*:*:*

Information

Published : 2013-05-10 11:42

Updated : 2017-08-29 01:33


NVD link : CVE-2013-0578

Mitre link : CVE-2013-0578


JSON object : View

Products Affected

ibm

  • sterling_multi-channel_fulfillment_solution
  • sterling_selling_and_fulfillment_foundation
CWE
CWE-287

Improper Authentication