CVE-2016-5894: IBM WebSphere Commerce

Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.

IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408.

Affected products

  • IBM WebSphere Commerce: version 7.0 only; version 7.0.0.1 only; version 7.0.0.2 only; version 7.0.0.3 only; version 7.0.0.4 only; version 7.0.0.5 only; …

Published 2017-03-08. Last modified 2026-06-17.