VYPR
High severity8.8NVD Advisory· Published Mar 31, 2017· Updated Jun 17, 2026

CVE-2016-8917

CVE-2016-8917

Description

IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000943.

Affected products

7
  • cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.2.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:sterling_selling_and_fulfillment_foundation:9.5.0:*:*:*:*:*:*:*
  • Range: 9.2 - 9.5
  • IBM Corporation/Sterling Order Managementv5
    Range: 8.5

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.