Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through 6.0.0.11, and 7.0.x through 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote attackers to obtain sensitive information via a padding oracle attack that targets certain UTF-8 processing of the krypto parameter, and leverages unspecified browser access or traffic-log access.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
IBM WebSphere Commerce Enterprise 信息泄露漏洞
Vulnerability Description
IBM WebSphere Commerce Enterprise是美国IBM公司的一套电子商务解决方案。该方案主要用于大容量的B2C和B2B业务模型以及多个电子商务站点的高级平台。 IBM WebSphere Commerce Enterprise 5.6.x至5.6.1.5版本,6.0.x至6.0.0.11版本,7.0.x至7.0.0.7版本中存在漏洞,该漏洞源于程序对storefront Web请求没有使用适当的加密算法。远程攻击者可通过padding oracle攻击目标特定的UTF-8处理kry
CVSS Information
N/A
Vulnerability Type
N/A