IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/82339 | vdb entry |
http://www-01.ibm.com/support/docview.wss?uid=swg1ID358571 | vendor advisory |
http://www-01.ibm.com/support/docview.wss?uid=swg21631302 | vendor advisory |