First published: Wed Mar 08 2017(Updated: )
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | =7.0 | |
IBM WebSphere Commerce | =7.0.0.1 | |
IBM WebSphere Commerce | =7.0.0.2 | |
IBM WebSphere Commerce | =7.0.0.3 | |
IBM WebSphere Commerce | =7.0.0.4 | |
IBM WebSphere Commerce | =7.0.0.5 | |
IBM WebSphere Commerce | =7.0.0.6 | |
IBM WebSphere Commerce | =7.0.0.7 | |
IBM WebSphere Commerce | =7.0.0.8 | |
IBM WebSphere Commerce | =7.0.0.9 | |
IBM WebSphere Commerce | =8.0.0.0 | |
IBM WebSphere Commerce | =8.0.0.1 | |
IBM WebSphere Commerce | =8.0.0.2 | |
IBM WebSphere Commerce | =8.0.0.3 | |
IBM WebSphere Commerce | =8.0.0.4 | |
IBM WebSphere Commerce | =8.0.0.5 | |
IBM WebSphere Commerce | =8.0.0.6 | |
IBM WebSphere Commerce | =8.0.0.7 | |
IBM WebSphere Commerce | =8.0.0.8 | |
IBM WebSphere Commerce | =8.0.0.9 | |
IBM WebSphere Commerce | =8.0.0.10 | |
IBM WebSphere Commerce | =8.0.0.11 | |
IBM WebSphere Commerce | =8.0.0.12 | |
IBM WebSphere Commerce | =8.0.0.13 | |
IBM WebSphere Commerce | =8.0.0.14 | |
IBM WebSphere Commerce | =8.0.0.15 | |
IBM WebSphere Commerce | =8.0.0.16 | |
IBM WebSphere Commerce | =8.0.0.17 | |
IBM WebSphere Commerce | =8.0.0.18 | |
IBM WebSphere Commerce | =8.0.0.19 | |
IBM WebSphere Commerce | =8.0.1.0 | |
IBM WebSphere Commerce | =8.0.1.1 | |
IBM WebSphere Commerce | =8.0.1.2 | |
IBM WebSphere Commerce | =8.0.1.3 | |
IBM WebSphere Commerce | =8.0.1.4 | |
IBM WebSphere Commerce | =8.0.1.5 | |
IBM WebSphere Commerce | =8.0.1.6 | |
IBM WebSphere Commerce | =8.0.1.7 | |
IBM WebSphere Commerce | =8.0.1.8 | |
IBM WebSphere Commerce | =8.0.1.9 | |
IBM WebSphere Commerce | =8.0.1.11 | |
IBM WebSphere Commerce | =8.0.1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5894 is classified as a medium severity information disclosure vulnerability.
To mitigate CVE-2016-5894, apply the latest patches provided by IBM for the affected versions of WebSphere Commerce.
CVE-2016-5894 affects local users on systems running IBM WebSphere Commerce versions 7.0 and 8.0.
CVE-2016-5894 allows a local user to view plain text passwords, potentially compromising account security.
There is no official workaround for CVE-2016-5894; applying patches is the recommended solution.