CVE-2025-42906
- EPSS 0.06%
- Veröffentlicht 14.10.2025 00:17:48
- Zuletzt bearbeitet 14.10.2025 19:36:29
SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed. This could potentially bypass co...
CVE-2025-27435
- EPSS 0.07%
- Veröffentlicht 08.04.2025 07:13:49
- Zuletzt bearbeitet 08.04.2025 18:13:53
Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, henc...
CVE-2025-26654
- EPSS 0.01%
- Veröffentlicht 08.04.2025 07:13:04
- Zuletzt bearbeitet 08.04.2025 18:13:53
SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality ...
CVE-2025-27434
- EPSS 0.19%
- Veröffentlicht 11.03.2025 01:15:36
- Zuletzt bearbeitet 11.03.2025 01:15:36
Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead...
CVE-2025-24875
- EPSS 0.04%
- Veröffentlicht 11.02.2025 01:15:11
- Zuletzt bearbeitet 18.02.2025 18:15:34
SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and m...
CVE-2025-24874
- EPSS 0.08%
- Veröffentlicht 11.02.2025 01:15:11
- Zuletzt bearbeitet 18.02.2025 18:15:34
SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of ...
CVE-2024-47577
- EPSS 0.07%
- Veröffentlicht 10.12.2024 01:15:05
- Zuletzt bearbeitet 10.12.2024 01:15:05
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorde...
CVE-2024-41733
- EPSS 0.39%
- Veröffentlicht 13.08.2024 04:15:08
- Zuletzt bearbeitet 12.09.2024 13:55:49
In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond thi...
CVE-2024-39597
- EPSS 0.19%
- Veröffentlicht 09.07.2024 04:15:13
- Zuletzt bearbeitet 21.11.2024 09:28:05
In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and registration is activated, without requiring the merchant to approve the account beforehand. If the s...
CVE-2022-41204
- EPSS 0.42%
- Veröffentlicht 11.10.2022 21:15:26
- Zuletzt bearbeitet 20.05.2025 16:15:22
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This ...