First published: Tue Mar 19 2013(Updated: )
IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Sterling Multi-Channel Fulfillment Solution | =8.0 | |
IBM Sterling Selling and Fulfillment Foundation | =8.5 | |
IBM Sterling Selling and Fulfillment Foundation | =9.0 | |
IBM Sterling Selling and Fulfillment Foundation | =9.1.0 | |
IBM Sterling Selling and Fulfillment Foundation | =9.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.