[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-6211Date: (C)2015-05-28   (M)2023-12-22


The command-line scripts in IBM WebSphere Commerce 6.0 through 6.0.0.11, 7.0 through 7.0.0.9, and 7.0 Feature Pack 2 through 8, when debugging is configured, do not properly restrict the logging of personal data, which allows local users to obtain sensitive information by reading a log file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 2.1
Exploit Score: 3.9
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1032248
JR52117
JR52983
http://www-01.ibm.com/support/docview.wss?uid=swg21883875

CPE    22
cpe:/a:ibm:websphere_commerce:7.0.0.3
cpe:/a:ibm:websphere_commerce:7.0.0.2
cpe:/a:ibm:websphere_commerce:7.0.0.1
cpe:/a:ibm:websphere_commerce:7.0.0.7
...
CWE    1
CWE-200

© SecPod Technologies