9.1
CVE-2024-33003
- EPSS 0.49%
- Published 13.08.2024 04:15:07
- Last modified 16.09.2024 16:22:07
- Source cna@sap.com
- Teams watchlist Login
- Open Login
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.
Data is provided by the National Vulnerability Database (NVD)
SAP ≫ Commerce Cloud Version1811
SAP ≫ Commerce Cloud Version1905
SAP ≫ Commerce Cloud Version2005
SAP ≫ Commerce Cloud Version2011
SAP ≫ Commerce Cloud Version2105
SAP ≫ Commerce Cloud Version2205
SAP ≫ Commerce Cloud Versioncom_cloud_2211
SAP ≫ Commerce Cloud Versionhy_com_1808
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.49% | 0.648 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
cna@sap.com | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.