CPE
An unpatched authorization bypass vulnerability in the sfturing hosp_order component allows remote attackers to manipulate the userIdenf parameter within OrderController.java to gain unauthorized access.