PT-2016-3216 · Ibm · Ibm Websphere Commerce+2
Publicado
2016-10-24
·
Atualizado
2019-10-02
·
CVE-2016-6090
CVSS v3.1
10
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Commerce (affected versions not specified)
IBM WebSphere Commerce Developer (affected versions not specified)
IBM Commerce on Cloud (affected versions not specified)
Description
The issue is related to a lack of protection for service data, which could allow an attacker to disclose protected information, perform actions on behalf of an administrator, or cause a denial of service.
Recommendations
For IBM WebSphere Commerce, consider restricting access to sensitive data until a fix is available.
For IBM WebSphere Commerce Developer, restrict access to administrative operations to minimize the risk of exploitation.
For IBM Commerce on Cloud, avoid using unprotected service data in administrative tasks until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Commerce On Cloud
Ibm Websphere Commerce
Ibm Websphere Commerce Developer