First published: Wed Feb 01 2017(Updated: )
IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performing of unauthorized administrative operations, and potentially causing a denial of service.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | >=6.0.0.0<=6.0.0.11 | |
IBM WebSphere Commerce | >=7.0.0.0<=7.0.0.9 | |
IBM WebSphere Commerce | >=8.0.0.0<=8.0.0.16 | |
IBM WebSphere Commerce | >=8.0.1.0<=8.0.1.8 | |
IBM WebSphere Commerce | =8.0.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6090 is considered a high severity vulnerability due to its potential to disclose personal user data and perform unauthorized administrative actions.
To fix CVE-2016-6090, update IBM WebSphere Commerce to a patched version as recommended by IBM.
CVE-2016-6090 can be exploited to disclose user personal data and may facilitate unauthorized administrative operations.
CVE-2016-6090 affects IBM WebSphere Commerce versions 6.0.0.0 to 6.0.0.11, 7.0.0.0 to 7.0.0.9, 8.0.0.0 to 8.0.0.16, 8.0.1.0 to 8.0.1.8, and the specific version 8.0.3.0.
The potential impacts of CVE-2016-6090 include unauthorized access to personal data, unauthorized administrative actions, and possible denial of service.