Information Disclosure in IBM Sterling Multi-Channel Fulfillment Solution and Selling and Fulfillment Foundation
CVE-2013-0578
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 10 May 2013
Summary
The Sterling Order Management APIs in specific versions of IBM Sterling Multi-Channel Fulfillment Solution and Selling and Fulfillment Foundation have a significant security vulnerability. This flaw arises when the API tester is enabled, which does not require administrative credentials, allowing remote authenticated users to access sensitive information stored in the database via requests to the API tester URI. This could potentially expose critical information to unauthorized users, posing a serious risk to data confidentiality.
References
Timeline
Vulnerability published
Vulnerability Reserved