9.1

CVE-2024-33003

Information Disclosure Vulnerability in SAP Commerce Cloud

Some OCC API endpoints in SAP Commerce Cloud
allows Personally Identifiable Information (PII) data, such as passwords, email
addresses, mobile numbers, coupon codes, and voucher codes, to be included in
the request URL as query or path parameters. On successful exploitation, this
could lead to a High impact on confidentiality and integrity of the
application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Commerce Cloud Version 1811
SAP ≫ Commerce Cloud Version 1905
SAP ≫ Commerce Cloud Version 2005
SAP ≫ Commerce Cloud Version 2011
SAP ≫ Commerce Cloud Version 2105
SAP ≫ Commerce Cloud Version 2205
SAP ≫ Commerce Cloud Version com_cloud_2211
SAP ≫ Commerce Cloud Version hy_com_1808
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.372
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
SAP 7.4 2.2 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://url.sap/sapsecuritypatchday
Vendor Advisory
https://me.sap.com/notes/3459935
Permissions Required