{"api_version":"1","generated_at":"2026-07-24T20:07:56+00:00","cve":"CVE-2010-2639","urls":{"html":"https://cve.report/CVE-2010-2639","api":"https://cve.report/api/cve/CVE-2010-2639.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2639","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2639"},"summary":{"title":"CVE-2010-2639","description":"IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging system to the RunTimeProfileCacheCmdImpl class, related to the caching of mutable objects and \"concurrency issues.\"","state":"PUBLISHED","assigner":"mitre","published_at":"2010-12-06 20:12:58","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securitytracker.com/id?1024845","name":"http://www.securitytracker.com/id?1024845","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM WebSphere Commerce May Disclose One User's Messages to Another User - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg24028397","name":"http://www-01.ibm.com/support/docview.wss?uid=swg24028397","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM JR38114: Potential security exposure in the outbound messaging system - United States","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1JR38114","name":"http://www-1.ibm.com/support/docview.wss?uid=swg1JR38114","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"JR38114: CMVC 205725 - STOP RUNTIMEPROFILECACHECMDIMPL CACHING MUTABLE   OBJECTS MODIFIED IN OTHER CONTROLLER/TASK CMNDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63406","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63406","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2639","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2639","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2639","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_commerce","cpe6":"7.0","cpe7":"*","cpe8":"enterprise","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"2639","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"websphere_commerce","cpe6":"7.0.0.1","cpe7":"*","cpe8":"enterprise","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:39:37.939Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1024845","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1024845"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg24028397"},{"name":"JR38114","tags":["vendor-advisory","x_refsource_AIXAPAR","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1JR38114"},{"name":"wcs-outboundmessage-info-disc(63406)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63406"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-11-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging system to the RunTimeProfileCacheCmdImpl class, related to the caching of mutable objects and \"concurrency issues.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1024845","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1024845"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg24028397"},{"name":"JR38114","tags":["vendor-advisory","x_refsource_AIXAPAR"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg1JR38114"},{"name":"wcs-outboundmessage-info-disc(63406)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63406"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-2639","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging system to the RunTimeProfileCacheCmdImpl class, related to the caching of mutable objects and \"concurrency issues.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1024845","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1024845"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg24028397","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg24028397"},{"name":"JR38114","refsource":"AIXAPAR","url":"http://www-1.ibm.com/support/docview.wss?uid=swg1JR38114"},{"name":"wcs-outboundmessage-info-disc(63406)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/63406"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-2639","datePublished":"2010-12-06T20:00:00.000Z","dateReserved":"2010-07-06T00:00:00.000Z","dateUpdated":"2024-08-07T02:39:37.939Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-12-06 20:12:58","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_commerce:7.0:*:enterprise:*:*:*:*:*","matchCriteriaId":"1B1C5DE8-08DD-47CE-B323-8ADC06EA1066"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:websphere_commerce:7.0.0.1:*:enterprise:*:*:*:*:*","matchCriteriaId":"908A9A8C-81DA-4315-917E-12E33FAC6B9E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2639","Ordinal":"1","Title":"CVE-2010-2639","CVE":"CVE-2010-2639","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2639","Ordinal":"1","NoteData":"IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging system to the RunTimeProfileCacheCmdImpl class, related to the caching of mutable objects and \"concurrency issues.\"","Type":"Description","Title":"CVE-2010-2639"},{"CveYear":"2010","CveId":"2639","Ordinal":"2","NoteData":"2010-12-06","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"2639","Ordinal":"3","NoteData":"2017-08-16","Type":"Other","Title":"Modified"}]}}}