PT-2016-3216 · Ibm · Ibm Websphere Commerce+2

Publicado

2016-10-24

·

Atualizado

2019-10-02

·

CVE-2016-6090

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM WebSphere Commerce (affected versions not specified) IBM WebSphere Commerce Developer (affected versions not specified) IBM Commerce on Cloud (affected versions not specified)
Description The issue is related to a lack of protection for service data, which could allow an attacker to disclose protected information, perform actions on behalf of an administrator, or cause a denial of service.
Recommendations For IBM WebSphere Commerce, consider restricting access to sensitive data until a fix is available. For IBM WebSphere Commerce Developer, restrict access to administrative operations to minimize the risk of exploitation. For IBM Commerce on Cloud, avoid using unprotected service data in administrative tasks until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02547
CVE-2016-6090

Produtos afetados

Ibm Commerce On Cloud
Ibm Websphere Commerce
Ibm Websphere Commerce Developer