CVE-2016-5894

Severity
5.1MEDIUM
EPSS
0.1%
top 82.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 8
Latest updateMay 13

Description

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 1.4 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9xhp-r5x3-pvv6: IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 72022-05-13
CVEList
CVE-2016-5894: IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 72017-03-08
CVE-2016-5894 (MEDIUM CVSS 5.1) | IBM WebSphere Commerce Enterprise | cvebase.io