Session Identifier Exposure in IBM Sterling Order Management
CVE-2016-5953
3.7LOW
Summary
IBM Sterling Order Management has a security issue where session identifiers are transmitted within the URL. When users attempt to access certain views without the necessary permissions, the system generates an error page that inadvertently exposes the encoded session identifier in Base64 format within the URL. This exposure can potentially lead to session hijacking if an attacker obtains the URL. It is crucial for users to implement proper security measures to prevent unauthorized access.
Affected Version(s)
Sterling Order Management 8.5
Sterling Order Management 8.0
Sterling Order Management 9.1
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved