Show filters
48 Total Results
Displaying 31-40 of 48
Sort by:
Attacker Value
Unknown

CVE-2013-2993

Disclosure Date: August 01, 2013 (last updated October 05, 2023)
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user's active session via unknown vectors.
0
Attacker Value
Unknown

CVE-2013-0523

Disclosure Date: June 21, 2013 (last updated October 05, 2023)
IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through 6.0.0.11, and 7.0.x through 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote attackers to obtain sensitive information via a padding oracle attack that targets certain UTF-8 processing of the krypto parameter, and leverages unspecified browser access or traffic-log access.
0
Attacker Value
Unknown

CVE-2012-4855

Disclosure Date: March 05, 2013 (last updated October 05, 2023)
Unspecified vulnerability in the web services framework in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to cause a denial of service (login outage) via unknown vectors.
0
Attacker Value
Unknown

CVE-2012-4830

Disclosure Date: October 01, 2012 (last updated October 05, 2023)
Unspecified vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to obtain users' personal data via unknown vectors.
0
Attacker Value
Unknown

CVE-2012-3300

Disclosure Date: September 25, 2012 (last updated October 05, 2023)
IBM WebSphere Commerce 7.0 before 7.0.0.6, when persistent sessions and personalization IDs are enabled, allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-3298

Disclosure Date: September 25, 2012 (last updated October 05, 2023)
Unspecified vulnerability in the REST services framework in IBM WebSphere Commerce 7.0 Feature Pack 4 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unspecified vectors.
0
Attacker Value
Unknown

CVE-2011-3577

Disclosure Date: September 20, 2011 (last updated October 04, 2023)
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which has unspecified impact and attack vectors.
0
Attacker Value
Unknown

CVE-2010-2639

Disclosure Date: December 06, 2010 (last updated October 04, 2023)
IBM WebSphere Commerce Enterprise 7.0 before 7.0.0.2 allows remote attackers to read messages intended for other recipients via vectors involving access by the outbound messaging system to the RunTimeProfileCacheCmdImpl class, related to the caching of mutable objects and "concurrency issues."
0
Attacker Value
Unknown

CVE-2010-2636

Disclosure Date: November 09, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in sample store pages in IBM WebSphere Commerce 7.0 before 7.0.0.1 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
0
Attacker Value
Unknown

CVE-2010-2635

Disclosure Date: November 09, 2010 (last updated October 04, 2023)
SQL injection vulnerability in IBM WebSphere Commerce 6.0 before 6.0.0.10 allows remote authenticated users to execute arbitrary SQL commands via unspecified parameters to "Commerce Organization Admin Console JavaServer pages."
0