IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9991
Reference (s):
- BID:96084
- URL: http://www.securityfocus.com/bid/96084
- http://www-01.ibm.com/support/docview.wss?uid=swg21998167
- https://exchange.xforce.ibmcloud.com/vulnerabilities/121314