VulnerabilityModified
CVE-2009-2751
IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.
MEDIUM 4.3EPSS 0.54%
Does this matter?
Lower severity and a low EPSS score (0.54%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 0.54% probability · 44th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-310
- Affected
- ibm/websphere commerce
- Source
- cve@mitre.org
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21418443Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1JR35136
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56089
- http://www-01.ibm.com/support/docview.wss?uid=swg21418443Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg1JR35136
- https://exchange.xforce.ibmcloud.com/vulnerabilities/56089
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.