IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.
2017-02-01T22:59:00.573
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 3.7 (LOW)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | sterling_selling_and_fulfillment_foundation | 9.1.0 | Yes |
Application | ibm | sterling_selling_and_fulfillment_foundation | 9.2.0 | Yes |
Application | ibm | sterling_selling_and_fulfillment_foundation | 9.2.1 | Yes |
Application | ibm | sterling_selling_and_fulfillment_foundation | 9.3 | Yes |
Application | ibm | sterling_selling_and_fulfillment_foundation | 9.4 | Yes |
Application | ibm | sterling_selling_and_fulfillment_foundation | 9.5 | Yes |