Ibm Websphere Commerce Enterprise vulnerabilities
5 known vulnerabilities affecting ibm/websphere_commerce_enterprise.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2018-1541MEDIUMCVSS 5.4vV7vV8+1 more2018-10-24
CVE-2018-1541 [MEDIUM] CWE-79 CVE-2018-1541: IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnera
IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142596.
cvelistv5nvd
CVE-2017-1484MEDIUMCVSS 4.3v7.0v8.02017-11-27
CVE-2017-1484 [MEDIUM] CWE-200 CVE-2017-1484: IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an a
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacker to obtain information such as user personal data. IBM X-Force ID: 128622.
cvelistv5nvd
CVE-2017-1569HIGHCVSS 7.5v7.0v8.02017-10-03
CVE-2017-1569 [HIGH] CVE-2017-1569: IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that c
IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that could cause a denial of service. IBM X-Force ID: 131779.
cvelistv5nvd
CVE-2017-1398MEDIUMCVSS 6.1v6.0v7.0+1 more2017-07-10
CVE-2017-1398 [MEDIUM] CWE-601 CVE-2017-1398: IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allo
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 6.0, 7.0, and 8.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious
cvelistv5nvd
CVE-2015-5015MEDIUMCVSS 5.0≤ 7.0.0.92015-11-08
CVE-2015-5015 [MEDIUM] CWE-200 CVE-2015-5015: IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to o
IBM WebSphere Commerce Enterprise 7.0.0.9 and 8.x before Feature Pack 8 allows remote attackers to obtain sensitive information via a crafted REST URL.
nvd