CVE-2009-2751

IBM WebSphere Commerce 7.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.

References (3)

Core 3
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg1JR35136
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56089
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21418443

Scores

EPSS 0.0054
EPSS Percentile 42.2%

Details

CWE
CWE-310
Status published
Products (1)
ibm/websphere_commerce 7.0
Published Feb 05, 2010
Tracked Since Feb 18, 2026