Known vulnerabilities in IBM WebSphere Commerce
Vendor:
IBM Corporation
Software:
IBM WebSphere Commerce
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_websphere_commerce:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
3
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
9.0.0.7
9.0.0.6
9.0.0.5
9.0.0.4
9.0.0.3
9.0.0.2
9.0.0.1
9.0.0.0
8.0.3.4
8.0.3.3
8.0.3.2
8.0.3.1
8.0.3.0
8.0.1.11
8.0.1.10
8.0.1.9
8.0.0.18
8.0.0.17
8.0.0.0
8.0.1.8
8.0.1.7
8.0.1.6
8.0.1.5
8.0.1.4
8.0.1.3
8.0.0.16
8.0.0.15
8.0.0.14
8.0.0.13
8.0.0.12
8.0.0.11
8.0.0.10
8.0.1.1
8.0.1.0
8.0.1.2
8.0.0.7
8.0.0.6
8.0.0.5
8.0.0.9
8.0.0.8
8.0.0.4
8.0.0.3
8.0.0.1
8.0.0.2
8.0
7.0.0.9
7.0.0.8
5.6.1
7.0.0.7
5.6.1.2
5.6.1.1
5.6.1.4
5.6.1.3
5.6.1.5
7.0.0.6
7.0.0.4
7.0.0.5
6.0
6.0.0.11
6.0.0.10
7.0.0.3
7.0.0.2
7.0.0.1
6.0.0.9
6.0.0.8
6.0.0.7
7.0
6.0.0.6
6.0.0.5
6.0.0.4
6.0.0.3
6.0.0.2
6.0.0.1
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU15754 - Improper Control of Generation of Code ('Code Injection') CVE-2018-1808 |
CWE-94 | Low | 9.0.0.7 | 06.11.2018 |
SB2018110717 |
||
| #VU6388 - Session Fixation CVE-2017-1170 |
CWE-384 | Low | - | 26.04.2017 |
SB2017042602 |
||
| #VU531 - Exposure of sensitive information to an unauthorized actor CVE-2016-5986 |
CWE-200 | Low | - | 19.09.2016 |
SB2016091911 SB2017050833 |