CVE-2016-5953

3.7LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 February 2017

Summary

IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.

Affected Version(s)

Sterling Order Management 8.5

Sterling Order Management 8.0

Sterling Order Management 9.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.