Vulnerabilities > SAP > Commerce Cloud > 2011

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2024-33003 Unspecified vulnerability in SAP Commerce Cloud
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters.
network
low complexity
sap
critical
9.1
2021-01-12 CVE-2021-21445 HTTP Request Smuggling vulnerability in SAP Commerce Cloud
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user.
network
low complexity
sap CWE-444
5.4