Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2009-2956

The (1) Net.Commerce and (2) Net.Data components in IBM WebSphere Commerce Suite store sensitive information under the web root with insufficient access control, which allows remote attackers to discover passwords, and database and filesystem details, via direct requests for configuration files.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.3%
CVSS Severity
CVSS v2 Score 5.0
Products affected by CVE-2009-2956


Contact Us

Shodan ® - All rights reserved