CVE-2016-5953

CVE-2016-5953

IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.

Source: CVE-2016-5953

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다