PT-2016-3216 · Ibm · Ibm Websphere Commerce+2
Published
2016-10-24
·
Updated
2019-10-02
·
CVE-2016-6090
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM WebSphere Commerce (affected versions not specified)
IBM WebSphere Commerce Developer (affected versions not specified)
IBM Commerce on Cloud (affected versions not specified)
Description
The issue is related to a lack of protection for service data, which could allow an attacker to disclose protected information, perform actions on behalf of an administrator, or cause a denial of service.
Recommendations
For IBM WebSphere Commerce, consider restricting access to sensitive data until a fix is available.
For IBM WebSphere Commerce Developer, restrict access to administrative operations to minimize the risk of exploitation.
For IBM Commerce on Cloud, avoid using unprotected service data in administrative tasks until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Commerce On Cloud
Ibm Websphere Commerce
Ibm Websphere Commerce Developer