Vulnerabilities > SAP > Commerce Cloud

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2024-33003 Unspecified vulnerability in SAP Commerce Cloud
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters.
network
low complexity
sap
critical
9.1
2023-12-12 CVE-2023-42481 Weak Password Recovery Mechanism for Forgotten Password vulnerability in SAP Commerce Cloud 8.1
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP Commerce Cloud - Composable Storefront is used as storefront, due to weak access controls in place.
network
low complexity
sap CWE-640
8.1
2023-08-08 CVE-2023-37486 Information Exposure Through Caching vulnerability in SAP Commerce Cloud and Commerce Hycom
Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access information which would otherwise be restricted.
network
low complexity
sap CWE-524
7.5
2023-08-08 CVE-2023-39439 Empty Password in Configuration File vulnerability in SAP Commerce Cloud and Commerce Hycom
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.
network
low complexity
sap CWE-258
critical
9.8
2021-06-09 CVE-2021-33666 Cross-site Scripting vulnerability in SAP Commerce Cloud 100
When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware proliferation.
network
sap CWE-79
4.3
2021-01-12 CVE-2021-21445 HTTP Request Smuggling vulnerability in SAP Commerce Cloud
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user.
network
sap CWE-444
3.5
2020-11-10 CVE-2020-26809 Incorrect Default Permissions vulnerability in SAP Commerce Cloud
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders.
network
low complexity
sap CWE-276
5.0
2020-10-15 CVE-2020-6363 Insufficient Session Expiration vulnerability in SAP Commerce Cloud
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user.
network
sap CWE-613
4.9
2020-10-15 CVE-2020-6272 Cross-site Scripting vulnerability in SAP Commerce Cloud
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components.
network
sap CWE-79
3.5
2020-04-14 CVE-2020-6238 XXE vulnerability in SAP Commerce Cloud
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation.
network
low complexity
sap CWE-611
critical
9.3