Lucene search

K
nvd[email protected]NVD:CVE-2011-3577
HistorySep 20, 2011 - 10:55 a.m.

CVE-2011-3577

2011-09-2010:55:08
CWE-287
web.nvd.nist.gov
4

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

72.2%

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which has unspecified impact and attack vectors.

Affected configurations

Nvd
Node
ibmwebsphere_commerceMatch6.0.0.0
OR
ibmwebsphere_commerceMatch6.0.0.1
OR
ibmwebsphere_commerceMatch6.0.0.2
OR
ibmwebsphere_commerceMatch6.0.0.3
OR
ibmwebsphere_commerceMatch6.0.0.4
OR
ibmwebsphere_commerceMatch6.0.0.5
OR
ibmwebsphere_commerceMatch6.0.0.6
OR
ibmwebsphere_commerceMatch6.0.0.7
OR
ibmwebsphere_commerceMatch6.0.0.8
OR
ibmwebsphere_commerceMatch6.0.0.9
OR
ibmwebsphere_commerceMatch6.0.0.10
OR
ibmwebsphere_commerceMatch6.0.0.11
Node
ibmwebsphere_commerceMatch7.0
OR
ibmwebsphere_commerceMatch7.0.0.1
OR
ibmwebsphere_commerceMatch7.0.0.2
OR
ibmwebsphere_commerceMatch7.0.0.3
VendorProductVersionCPE
ibmwebsphere_commerce6.0.0.0cpe:2.3:a:ibm:websphere_commerce:6.0.0.0:*:*:*:*:*:*:*
ibmwebsphere_commerce6.0.0.1cpe:2.3:a:ibm:websphere_commerce:6.0.0.1:*:*:*:*:*:*:*
ibmwebsphere_commerce6.0.0.2cpe:2.3:a:ibm:websphere_commerce:6.0.0.2:*:*:*:*:*:*:*
ibmwebsphere_commerce6.0.0.3cpe:2.3:a:ibm:websphere_commerce:6.0.0.3:*:*:*:*:*:*:*
ibmwebsphere_commerce6.0.0.4cpe:2.3:a:ibm:websphere_commerce:6.0.0.4:*:*:*:*:*:*:*
ibmwebsphere_commerce6.0.0.5cpe:2.3:a:ibm:websphere_commerce:6.0.0.5:*:*:*:*:*:*:*
ibmwebsphere_commerce6.0.0.6cpe:2.3:a:ibm:websphere_commerce:6.0.0.6:*:*:*:*:*:*:*
ibmwebsphere_commerce6.0.0.7cpe:2.3:a:ibm:websphere_commerce:6.0.0.7:*:*:*:*:*:*:*
ibmwebsphere_commerce6.0.0.8cpe:2.3:a:ibm:websphere_commerce:6.0.0.8:*:*:*:*:*:*:*
ibmwebsphere_commerce6.0.0.9cpe:2.3:a:ibm:websphere_commerce:6.0.0.9:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

6.7

Confidence

Low

EPSS

0.004

Percentile

72.2%

Related for NVD:CVE-2011-3577