First published: Tue Sep 20 2011(Updated: )
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which has unspecified impact and attack vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | =6.0.0.7 | |
IBM WebSphere Commerce | =6.0.0.5 | |
IBM WebSphere Commerce | =6.0.0.10 | |
IBM WebSphere Commerce | =6.0.0.11 | |
IBM WebSphere Commerce | =6.0.0.2 | |
IBM WebSphere Commerce | =6.0.0.1 | |
IBM WebSphere Commerce | =6.0.0.8 | |
IBM WebSphere Commerce | =6.0.0.3 | |
IBM WebSphere Commerce | =6.0.0.4 | |
IBM WebSphere Commerce | =6.0.0.9 | |
IBM WebSphere Commerce | =6.0.0.6 | |
IBM WebSphere Commerce | =6.0.0.0 | |
IBM WebSphere Commerce | =7.0 | |
IBM WebSphere Commerce | =7.0.0.2 | |
IBM WebSphere Commerce | =7.0.0.1 | |
IBM WebSphere Commerce | =7.0.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2011-3577 is classified as unspecified, indicating potential risks in the implementation of Activity Token authentication.
To fix CVE-2011-3577, ensure that you apply the latest patches and updates provided by IBM for WebSphere Commerce.
CVE-2011-3577 affects IBM WebSphere Commerce versions 6.x from 6.0.0.1 to 6.0.0.11 and 7.x from 7.0.0.1 to 7.0.0.3.
CVE-2011-3577 can lead to unspecified impact on Web Services due to improper implementation of Activity Token authentication.
CVE-2011-3577 has unspecified attack vectors that could exploit the vulnerability in the authentication process.