First published: Mon Feb 15 2016(Updated: )
The Update Installer in IBM WebSphere Commerce Enterprise 7.0.0.8 and 7.0.0.9 does not properly replicate the search index, which allows attackers to obtain sensitive information via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | =7.0.0.8 | |
IBM WebSphere Commerce | =7.0.0.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7444 is classified as a medium severity vulnerability due to its potential to expose sensitive information.
To fix CVE-2015-7444, update IBM WebSphere Commerce to the latest version that addresses this vulnerability.
CVE-2015-7444 affects IBM WebSphere Commerce versions 7.0.0.8 and 7.0.0.9.
CVE-2015-7444 can potentially expose sensitive information through improper search index replication.
There are currently no documented workarounds for CVE-2015-7444, and it is recommended to apply patches immediately.