IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which has unspecified impact and attack vectors.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
http://secunia.com/advisories/45999 | third party advisory vendor advisory |
http://www.ibm.com/support/docview.wss?uid=swg24030908 | |
http://www.ibm.com/support/docview.wss?uid=swg1JR40420 | vendor advisory |
http://www.osvdb.org/75428 | vdb entry |
http://www.securityfocus.com/bid/49643 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/69838 | vdb entry |