Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9p3j-j69q-f44j

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.

IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.

EPSS

Процентиль: 35%
0.00141
Низкий

3.7 Low

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 3.7
nvd
около 9 лет назад

IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.

EPSS

Процентиль: 35%
0.00141
Низкий

3.7 Low

CVSS3

Дефекты

CWE-200