Total vulnerabilities in the database
orderdspc.d2w macro in IBM Net.Commerce 3.x allows remote attackers to execute arbitrary SQL queries by inserting them into the order_rn option of the report capability.
Software | From | Fixed in |
---|---|---|
ibm / net.commerce | 3.1.2 | 3.1.2.x |
ibm / net.commerce_hosting_server | 3.1.1 | 3.1.1.x |
ibm / net.commerce | 3.1 | 3.1.x |
ibm / net.commerce | 3.1.1 | 3.1.1.x |
ibm / websphere_commerce_suite | 4.1 | 4.1.x |
ibm / net.commerce | 3.2 | 3.2.x |
ibm / net.commerce | 2.0 | 2.0.x |
ibm / websphere_commerce_suite | 3.1.2 | 3.1.2.x |
ibm / net.commerce | 3.0 | 3.0.x |
ibm / websphere_commerce_suite | 4.1.1 | 4.1.1.x |
ibm / websphere_commerce_suite | 3.2 | 3.2.x |
ibm / net.commerce_hosting_server | 3.2 | 3.2.x |
ibm / net.commerce_hosting_server | 3.1.2 | 3.1.2.x |