SAP

Commerce

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 10.02.2026 03:03:52
  • Zuletzt bearbeitet 17.02.2026 15:24:36

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerabilit...

  • EPSS 0.04%
  • Veröffentlicht 10.02.2026 03:02:14
  • Zuletzt bearbeitet 17.02.2026 16:04:38

A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked out. This leads to high impact ...

  • EPSS 0.06%
  • Veröffentlicht 14.10.2025 00:17:48
  • Zuletzt bearbeitet 14.10.2025 19:36:29

SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed. This could potentially bypass co...

  • EPSS 0.21%
  • Veröffentlicht 08.04.2025 07:13:49
  • Zuletzt bearbeitet 08.04.2025 18:13:53

Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, henc...

  • EPSS 0.05%
  • Veröffentlicht 08.04.2025 07:13:04
  • Zuletzt bearbeitet 08.04.2025 18:13:53

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality ...

  • EPSS 0.24%
  • Veröffentlicht 11.03.2025 01:15:36
  • Zuletzt bearbeitet 11.03.2025 01:15:36

Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead...

  • EPSS 0.09%
  • Veröffentlicht 11.02.2025 01:15:11
  • Zuletzt bearbeitet 18.02.2025 18:15:34

SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces defense in depth against CSRF and m...

  • EPSS 0.1%
  • Veröffentlicht 11.02.2025 01:15:11
  • Zuletzt bearbeitet 18.02.2025 18:15:34

SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue support for this header in favor of ...

  • EPSS 0.04%
  • Veröffentlicht 10.12.2024 01:15:05
  • Zuletzt bearbeitet 10.12.2024 01:15:05

Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorde...

  • EPSS 0.53%
  • Veröffentlicht 13.08.2024 04:15:08
  • Zuletzt bearbeitet 12.09.2024 13:55:49

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond thi...