CVE-2018-1644: IBM WebSphere Commerce
Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 9.0.0.0 - 9.0.0.4, 8.0.0.0 - 8.0.0.19, 8.0.1.0 - 8.0.1.13, 8.0.3.0 - 8.0.3.6, 8.0.4.0 - 8.0.4.14, and 7.0.0.0 Feature Pack 8 could allow an authenticated user to obtain sensitive information about another user.
Affected products
- IBM WebSphere Commerce: from 8.0.0.0, up to and including 8.0.0.19; from 8.0.1.0, up to and including 8.0.1.13; from 8.0.3.0, up to and including 8.0.3.6; from 8.0.4.0, up to and including 8.0.4.14; from 9.0.0.0, up to and including 9.0.0.4; version 7.0 only
Published 2018-08-27. Last modified 2026-06-17.