First published: Fri Feb 05 2010(Updated: )
IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2752 is considered to be of medium severity due to the potential exposure of sensitive data.
To fix CVE-2009-2752, ensure that data in the IBM WebSphere Commerce 7.0 database is properly encrypted according to security best practices.
CVE-2009-2752 affects users of IBM WebSphere Commerce 7.0 who handle sensitive information in their databases.
CVE-2009-2752 puts any sensitive information stored in the database, such as customer data and payment information, at risk of exposure.
As a workaround for CVE-2009-2752, consider restricting database access to only trusted personnel until a proper fix is implemented.