PT-2016-3781 · Ibm · Ibm Websphere Commerce Enterprise

Published

2016-02-15

·

Updated

2016-03-02

·

CVE-2015-7444

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM WebSphere Commerce Enterprise versions 7.0.0.8 through 7.0.0.9
Description The issue concerns the Update Installer in IBM WebSphere Commerce Enterprise, which fails to properly replicate the search index. This allows attackers to obtain sensitive information via unspecified vectors.
Recommendations For versions 7.0.0.8 and 7.0.0.9, update to a version that properly replicates the search index to prevent sensitive information disclosure. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-7444

Affected Products

Ibm Websphere Commerce Enterprise