BM WebSphere Commerce contains a flaw that may lead to unauthorized disclosure of sensitive information. The issue is due to the program storing two unspecified passwords in plaintext in the configuration file. This may allow a local attacker to gain access to sensitive password information.