IBM Websphere Commerce Database Update Information Disclosure

low Nessus Plugin ID 16173

Synopsis

The remote web server is affected by an information disclosure issue.

Description

The remote host is running a version of IBM Websphere Commerce that may allow potentially confidential information to be accessed through the default user account. An attacker, exploiting this flaw, would only need to be able to make standard queries to the application server.

Solution

Contact WebSphere Commerce support to resolve the issue.

Plugin Details

Severity: Low

ID: 16173

File Name: websphere_user_info_disclosure.nasl

Version: 1.17

Type: remote

Family: CGI abuses

Published: 1/15/2005

Updated: 1/19/2021

Supported Sensors: Nessus

Risk Information

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 1.9

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Information

CPE: cpe:/a:ibm:websphere_commerce

Required KB Items: www/WebSphere

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 11/1/2004

Reference Information

BID: 11816

Secunia: 13234