IBM WebSphere Commerce Multiple Vulnerabilities
Last Update Date:
30 Jul 2013 14:10
Release Date:
30 Jul 2013
3897
Views
RISK: Medium Risk
TYPE: Servers - Web Servers
A vulnerability has been identified in IBM Websphere Commerce, which can be exploited by malicious people to bypass certain security restrictions.
- The vulnerability is caused due to an error within REST services, which can be exploited to run REST services as another user with a valid session.
- The vulnerability is caused due to web services not properly validating incoming requests, which can be exploited to run web service requests as another user that has an active session.
Impact
- Security Restriction Bypass
System / Technologies affected
- IBM Websphere Commerce 6.x
- IBM Websphere Commerce 7.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Apply APAR JR45420
Vulnerability Identifier
Source
Related Link
Share with