IBM Security Bulletin: IBM WebSphere Commerce could allow some server-side code injection (CVE-2018-1808)

Oct 25, 2018 9:00 am EDT

Categorized: Medium Severity

Share this post:

IBM WebSphere Commerce Enterprise, Professional and Developer could be vulnerable to server-side code injection.

CVE(s): CVE-2018-1808

Affected product(s) and affected version(s):

WebSphere Commerce versions 9.0.0.0 – 9.0.0.6

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10735905
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/149828



from IBM Product Security Incident Response Team https://ift.tt/2ELRF0G