Vulnerabilities > IBM > Sterling Selling AND Fulfillment Foundation

DATE CVE VULNERABILITY TITLE RISK
2017-06-08 CVE-2016-9991 Cross-Site Request Forgery (CSRF) vulnerability in IBM Sterling Selling and Fulfillment Foundation
IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.0
2017-03-31 CVE-2016-8917 Cross-Site Request Forgery (CSRF) vulnerability in IBM Sterling Selling and Fulfillment Foundation
IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.
network
low complexity
ibm CWE-352
8.8
2017-02-01 CVE-2016-5953 Information Exposure vulnerability in IBM Sterling Selling and Fulfillment Foundation
IBM Sterling Order Management transmits the session identifier within the URL.
network
high complexity
ibm CWE-200
3.7