CVE-2015-7444

MEDIUM

IBM WebSphere Commerce Enterprise <7.0.0.9 - Info Disclosure

Title source: llm

Description

The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors.

Scores

CVSS v3 5.3
EPSS 0.0021
EPSS Percentile 43.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-200
Status draft

Affected Products (2)

ibm/websphere_commerce
ibm/websphere_commerce

Timeline

Published Feb 15, 2016
Tracked Since Feb 18, 2026