First published: Thu Aug 23 2018(Updated: )
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenticated user to obtain sensitive information about another user.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM WebSphere Commerce | >=8.0.0.0<=8.0.0.19 | |
IBM WebSphere Commerce | >=8.0.0.0<=8.0.0.19 | |
IBM WebSphere Commerce | >=8.0.0.0<=8.0.0.19 | |
IBM WebSphere Commerce | >=8.0.0.0<=8.0.0.19 | |
IBM WebSphere Commerce | >=8.0.1.0<=8.0.1.13 | |
IBM WebSphere Commerce | >=8.0.1.0<=8.0.1.13 | |
IBM WebSphere Commerce | >=8.0.1.0<=8.0.1.13 | |
IBM WebSphere Commerce | >=8.0.1.0<=8.0.1.13 | |
IBM WebSphere Commerce | >=8.0.3.0<=8.0.3.6 | |
IBM WebSphere Commerce | >=8.0.3.0<=8.0.3.6 | |
IBM WebSphere Commerce | >=8.0.3.0<=8.0.3.6 | |
IBM WebSphere Commerce | >=8.0.3.0<=8.0.3.6 | |
IBM WebSphere Commerce | >=8.0.4.0<=8.0.4.14 | |
IBM WebSphere Commerce | >=8.0.4.0<=8.0.4.14 | |
IBM WebSphere Commerce | >=8.0.4.0<=8.0.4.14 | |
IBM WebSphere Commerce | >=8.0.4.0<=8.0.4.14 | |
IBM WebSphere Commerce | >=9.0.0.0<=9.0.0.4 | |
IBM WebSphere Commerce | >=9.0.0.0<=9.0.0.4 | |
IBM WebSphere Commerce | >=9.0.0.0<=9.0.0.4 | |
IBM WebSphere Commerce | >=9.0.0.0<=9.0.0.4 | |
IBM WebSphere Commerce | =7.0-feature_pack_8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1644 is rated as medium severity, allowing authenticated users to access sensitive information of other users.
To mitigate CVE-2018-1644, you should upgrade IBM WebSphere Commerce to the latest patched version available.
CVE-2018-1644 affects IBM WebSphere Commerce versions from 7.0 Feature Pack 8 up to 9.0.0.4.
CVE-2018-1644 can be exploited by authenticated users with access to the affected IBM WebSphere Commerce applications.
CVE-2018-1644 can potentially expose sensitive user information such as personal data and account details.