IBM Security Bulletin: Information disclosure vulnerability could expose user personal data in IBM WebSphere Commerce (CVE-2015-5015)

WebSphere Commerce REST services could allow a remote unauthenticated attacker to expose some personal user data using a specially-crafted URL. CVE(s):   CVE-2015-5015 Affected product(s) and affected version(s): ...

from IBM Product Security Incident Response Team http://ift.tt/1NePA4Y