SAP

Commerce Cloud

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 15.10.2020 02:15:12
  • Zuletzt bearbeitet 21.11.2024 05:35:34

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change thei...

  • EPSS 0.16%
  • Veröffentlicht 15.10.2020 02:15:12
  • Zuletzt bearbeitet 21.11.2024 05:35:25

SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later trig...

  • EPSS 0.41%
  • Veröffentlicht 14.04.2020 19:15:18
  • Zuletzt bearbeitet 21.11.2024 05:35:21

SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.

  • EPSS 0.25%
  • Veröffentlicht 14.04.2020 19:15:18
  • Zuletzt bearbeitet 21.11.2024 05:35:20

SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.

  • EPSS 0.37%
  • Veröffentlicht 10.03.2020 21:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:17

The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without escaping/sanitization, leading to Ref...

  • EPSS 0.4%
  • Veröffentlicht 10.03.2020 21:15:14
  • Zuletzt bearbeitet 21.11.2024 05:35:17

The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.

Warnung
  • EPSS 50.7%
  • Veröffentlicht 14.08.2019 14:15:16
  • Zuletzt bearbeitet 27.01.2025 21:44:13

Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.

  • EPSS 0.61%
  • Veröffentlicht 14.08.2019 14:15:16
  • Zuletzt bearbeitet 21.11.2024 04:16:42

SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby co...

  • EPSS 0.64%
  • Veröffentlicht 10.07.2019 19:15:10
  • Zuletzt bearbeitet 21.11.2024 04:16:40

SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.