Session Identifier Exposure in IBM Sterling Order Management
CVE-2016-5953

3.7LOW

Key Information:

Vendor
IBM
Vendor
CVE Published:
1 February 2017

Summary

IBM Sterling Order Management has a security issue where session identifiers are transmitted within the URL. When users attempt to access certain views without the necessary permissions, the system generates an error page that inadvertently exposes the encoded session identifier in Base64 format within the URL. This exposure can potentially lead to session hijacking if an attacker obtains the URL. It is crucial for users to implement proper security measures to prevent unauthorized access.

Affected Version(s)

Sterling Order Management 8.5

Sterling Order Management 8.0

Sterling Order Management 9.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.