CVE-2016-6090: IBM WebSphere Commerce

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

IBM WebSphere Commerce contains an unspecified vulnerability that could allow disclosure of user personal data, performing of unauthorized administrative operations, and potentially causing a denial of service.

Affected products

  • IBM WebSphere Commerce: from 6.0.0.0, up to and including 6.0.0.11; from 7.0.0.0, up to and including 7.0.0.9; from 8.0.0.0, up to and including 8.0.0.16; from 8.0.1.0, up to and including 8.0.1.8; version 8.0.3.0 only

Published 2017-02-01. Last modified 2026-06-17.