IBM WebSphere Commerce Default User Information Disclosure Vulnerability
BID:11816
Info
IBM WebSphere Commerce Default User Information Disclosure Vulnerability
| Bugtraq ID: | 11816 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2004 12:00AM |
| Updated: | Dec 03 2004 12:00AM |
| Credit: | Disclosed by the vendor. |
| Vulnerable: |
IBM WebSphere Commerce 5.6 IBM WebSphere Commerce 5.5 IBM WebSphere Commerce 5.4 IBM WebSphere Commerce 5.1 |
| Not Vulnerable: | |
Discussion
IBM WebSphere Commerce Default User Information Disclosure Vulnerability
It is reported that WebSphere Commerce is susceptible to an information disclosure vulnerability.
This vulnerability may result in potentially sensitive customer data being available to the default user, possibly allowing unintended users to gain access to it.
This vulnerability is reported to affect versions 5.1, 5.4, 5.5, and 5.6.
It is reported that WebSphere Commerce is susceptible to an information disclosure vulnerability.
This vulnerability may result in potentially sensitive customer data being available to the default user, possibly allowing unintended users to gain access to it.
This vulnerability is reported to affect versions 5.1, 5.4, 5.5, and 5.6.
Exploit / POC
IBM WebSphere Commerce Default User Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
IBM WebSphere Commerce Default User Information Disclosure Vulnerability
Solution:
WebSphere Commerce fixes can be obtained by contacting the vendor.
Users should follow the steps in the referenced IBM Security Update to determine if they are affected.
Solution:
WebSphere Commerce fixes can be obtained by contacting the vendor.
Users should follow the steps in the referenced IBM Security Update to determine if they are affected.
References
IBM WebSphere Commerce Default User Information Disclosure Vulnerability
References:
References:
- Security update 1187876 (IBM)