CVE-2016-5953
Severity CVSS v4.0:
Pending analysis
Type:
CWE-200
Information Leak / Disclosure
Publication date:
01/02/2017
Last modified:
20/04/2025
Description
IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.
Impact
Base Score 3.x
3.70
Severity 3.x
LOW
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.5:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



