CVE-2016-0225

EUVD-2016-0260
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.9 allows remote authenticated Commerce Accelerator administrators to obtain sensitive information via unspecified vectors.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.9 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Affected Products (NVD)
VendorProductVersion
ibmwebsphere_commerce
6.0.0.0
ibmwebsphere_commerce
6.0.0.1
ibmwebsphere_commerce
6.0.0.2
ibmwebsphere_commerce
6.0.0.3
ibmwebsphere_commerce
6.0.0.4
ibmwebsphere_commerce
6.0.0.5
ibmwebsphere_commerce
6.0.0.6
ibmwebsphere_commerce
6.0.0.7
ibmwebsphere_commerce
6.0.0.8
ibmwebsphere_commerce
6.0.0.9
ibmwebsphere_commerce
6.0.0.10
ibmwebsphere_commerce
6.0.0.11
ibmwebsphere_commerce
7.0
ibmwebsphere_commerce
7.0.0.1
ibmwebsphere_commerce
7.0.0.2
ibmwebsphere_commerce
7.0.0.3
ibmwebsphere_commerce
7.0.0.4
ibmwebsphere_commerce
7.0.0.5
ibmwebsphere_commerce
7.0.0.6
ibmwebsphere_commerce
7.0.0.7
ibmwebsphere_commerce
7.0.0.8
ibmwebsphere_commerce
7.0.0.9
𝑥
= Vulnerable software versions