CVE-2016-5953: IBM Sterling Selling And Fulfillment Foundation

Low severity, CVSS 3.7. EPSS: 0.8% chance of exploitation in the next 30 days.

IBM Sterling Order Management transmits the session identifier within the URL. When a user is unable to view a certain view due to not being allowed permissions, the website responds with an error page where the session identifier is encoded as Base64 in the URL.

Affected products

  • IBM Sterling Selling And Fulfillment Foundation: version 9.1.0 only; version 9.2.0 only; version 9.2.1 only; version 9.3 only; version 9.4 only; version 9.5 only

Published 2017-02-01. Last modified 2026-06-17.