Vulnerabilities > CVE-2023-37486 - Information Exposure Through Caching vulnerability in SAP Commerce Cloud and Commerce Hycom

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
sap
CWE-524

Summary

Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access information which would otherwise be restricted. On successful exploitation there could be a high impact on confidentiality with no impact on integrity and availability of the application.

Vulnerable Configurations

Part Description Count
Application
Sap
3

Common Weakness Enumeration (CWE)