CVE-2018-1644
Description
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenticated user to obtain sensitive information about another user.
CWE
- (none)
Affected
- IBM / WebSphere Commerce — v=7.0.0.0 [affected]; v=8.0.4.0 [affected]; v=8.0.4.14 [affected]; v=8.0.3.0 [affected]; v=8.0.3.6 [affected]; v=8.0.1.0 [affected]; v=8.0.1.13 [affected]; v=8.0.0.0 [affected]; v=8.0.0.19 [affected]; v=9.0.0.0 [affected]; v=9.0.0.4 [affected]; v=8.0.4.3 [affected]; v=8.0.4.4 [affected]; v=8.0.4.5 [affected]; v=8.0.4.6 [affected]; v=8.0.4.7 [affected]; v=8.0.4.8 [affected]; v=8.0.4.9 [affected]; v=8.0.4.10 [affected]; v=8.0.4.11 [affected]; v=8.0.4.12 [affected]; v=8.0.4.13 [affected]; v=8.0.3.1 [affected]; v=8.0.3.2 [affected]; v=8.0.3.3 [affected]; v=8.0.3.4 [affected]; v=8.0.3.5 [affected]; v=8.0.4.1 [affected]; v=8.0.4.2 [affected]; v=8.0.1.1 [affected]; v=8.0.1.2 [affected]; v=8.0.1.3 [affected]; v=8.0.1.4 [affected]; v=8.0.1.5 [affected]; v=8.0.1.6 [affected]; v=8.0.1.7 [affected]; v=8.0.1.8 [affected]; v=8.0.1.9 [affected]; v=8.0.1.10 [affected]; v=8.0.1.11 [affected]; v=8.0.1.12 [affected]; v=8.0.0.1 [affected]; v=8.0.0.2 [affected]; v=8.0.0.3 [affected]; v=8.0.0.4 [affected]; v=8.0.0.5 [affected]; v=8.0.0.6 [affected]; v=8.0.0.7 [affected]; v=8.0.0.8 [affected]; v=8.0.0.9 [affected]; v=8.0.0.10 [affected]; v=8.0.0.11 [affected]; v=8.0.0.12 [affected]; v=8.0.0.13 [affected]; v=8.0.0.14 [affected]; v=8.0.0.15 [affected]; v=8.0.0.16 [affected]; v=8.0.0.17 [affected]; v=8.0.0.18 [affected]; v=9.0.0.1 [affected]; v=9.0.0.2 [affected]; v=9.0.0.3 [affected]
CVSS
- 3.0 score=3.1 severity=LOW
CVSS:3.0/A:N/AC:H/AV:N/C:L/I:N/PR:L/S:U/UI:N/E:U/RC:C/RL:O
References
- http://www.ibm.com/support/docview.wss?uid=ibm10728829 x_refsource_CONFIRM
- https://exchange.xforce.ibmcloud.com/vulnerabilities/144589 vdb-entry, x_refsource_XF
Source
cvelistV5-main/cves/2018/1xxx/CVE-2018-1644.json