9.1
CVE-2024-33003
- EPSS 0.49%
- Veröffentlicht 13.08.2024 04:15:07
- Zuletzt bearbeitet 16.09.2024 16:22:07
- Quelle cna@sap.com
- Teams Watchlist Login
- Unerledigt Login
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Commerce Cloud Version1811
SAP ≫ Commerce Cloud Version1905
SAP ≫ Commerce Cloud Version2005
SAP ≫ Commerce Cloud Version2011
SAP ≫ Commerce Cloud Version2105
SAP ≫ Commerce Cloud Version2205
SAP ≫ Commerce Cloud Versioncom_cloud_2211
SAP ≫ Commerce Cloud Versionhy_com_1808
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.49% | 0.648 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.1 | 3.9 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
|
cna@sap.com | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.