CVE-2016-0225

MEDIUM

IBM WebSphere Commerce <7.0.0.9 - Info Disclosure

Title source: llm
STIX 2.1

Description

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.

References (2)

Core 2
Core References
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1JR54585
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21976623

Scores

CVSS v3 4.9
EPSS 0.0110
EPSS Percentile 61.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200 CWE-284
Status published
Products (22)
ibm/websphere_commerce 6.0.0.0
ibm/websphere_commerce 6.0.0.1
ibm/websphere_commerce 6.0.0.2
ibm/websphere_commerce 6.0.0.3
ibm/websphere_commerce 6.0.0.4
ibm/websphere_commerce 6.0.0.5
ibm/websphere_commerce 6.0.0.6
ibm/websphere_commerce 6.0.0.7
ibm/websphere_commerce 6.0.0.8
ibm/websphere_commerce 6.0.0.9
... and 12 more
Published Feb 29, 2016
Tracked Since Feb 18, 2026