Information Disclosure in IBM Sterling Multi-Channel Fulfillment Solution and Selling and Fulfillment Foundation
CVE-2013-0578

Currently unrated

Key Information:

Summary

The Sterling Order Management APIs in specific versions of IBM Sterling Multi-Channel Fulfillment Solution and Selling and Fulfillment Foundation have a significant security vulnerability. This flaw arises when the API tester is enabled, which does not require administrative credentials, allowing remote authenticated users to access sensitive information stored in the database via requests to the API tester URI. This could potentially expose critical information to unauthorized users, posing a serious risk to data confidentiality.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.