Information Disclosure Vulnerability in IBM WebSphere Commerce Products
CVE-2017-1484
4.3MEDIUM
Summary
IBM WebSphere Commerce products, including Enterprise, Professional, Express, and Developer versions 7.0 and 8.0, contain a vulnerability that may enable authenticated attackers to gain access to sensitive user information like personal data. This poses significant risks for data privacy and can lead to potential exploitation. Organizations utilizing these affected versions should ensure they have appropriate security measures in place and consider applying any available updates or patches.
Affected Version(s)
WebSphere Commerce Enterprise 7.0
WebSphere Commerce Enterprise 8.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved