First published: Fri Feb 05 2010(Updated: )
IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2751 is considered a moderate severity vulnerability due to the potential impact on session management and data security.
To fix CVE-2009-2751, it is recommended to upgrade IBM WebSphere Commerce to a version that separates cryptographic keys for different secure data.
CVE-2009-2751 affects users of IBM WebSphere Commerce version 7.0 specifically.
The potential risks of CVE-2009-2751 include unauthorized access to sensitive merchant data and session information.
There are no known effective workarounds for CVE-2009-2751 other than applying the recommended updates.