CVE-2017-1170
MEDIUMIBM WebSphere Commerce <8.0 - Privilege Escalation
Title source: llmDescription
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230.
Scores
CVSS v3
5.3
EPSS
0.0008
EPSS Percentile
23.7%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Classification
Status
published
Affected Products (33)
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
ibm/websphere_commerce
... and 18 more
Timeline
Published
Apr 26, 2017
Tracked Since
Feb 18, 2026