VULNERABILITY INTELLIGENCE

CVE-2011-3577

CVSS score10 HIGH
EPSS probability2.04%
CISA KEVNot currently listed
Published2011-09-20
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:N/C:C/I:C/A:C

Description

IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.3 does not properly implement Activity Token authentication for Web Services, which has unspecified impact and attack vectors.

Weakness classification

  • CWE-287: Improper Authentication

Primary references