Vulnerabilities (CVE)

Filtered by vendor Ibm Subscribe
Filtered by product Sterling Selling And Fulfillment Foundation
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-5953 1 Ibm 1 Sterling Selling And Fulfillment Foundation 2017-02-15 4.3 MEDIUM 3.7 LOW
IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.