CVE Database
/

CVE-2016-5953

Back to search

CVE-2016-5953

Published: Feb 1, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.

VendorProductVersions

IBM Corporation

Sterling Order Management

affected
8.5
affected
8.0
affected
9.1
affected
9.2
affected
9.2.1

+3 more versions

References

95431
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now