Cross-site Scripting Vulnerability in IBM Sterling Selling and Fulfillment Suite
CVE-2015-1911
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 25 May 2015
What is CVE-2015-1911?
A Cross-site Scripting (XSS) vulnerability exists in IBM Sterling Selling and Fulfillment Suite, specifically affecting Sterling Order Management 8.5, Sterling Selling and Fulfillment Foundation 9.0.0, and Sterling Field Sales (SFS) 9.0. The flaw allows remote attackers to inject arbitrary web scripts or HTML via crafted URLs, which could potentially lead to unauthorized actions and exposure of sensitive information.