SAP

Commerce

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 09.07.2024 04:15:13
  • Zuletzt bearbeitet 21.11.2024 09:28:05

In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and registration is activated, without requiring the merchant to approve the account beforehand. If the s...

  • EPSS 0.42%
  • Veröffentlicht 11.10.2022 21:15:26
  • Zuletzt bearbeitet 20.05.2025 16:15:22

An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This ...

  • EPSS 0.62%
  • Veröffentlicht 14.12.2021 16:15:09
  • Zuletzt bearbeitet 21.11.2024 06:27:10

If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backe...

  • EPSS 0.35%
  • Veröffentlicht 10.11.2021 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:24:16

SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Authenticated attackers will be able to access and edit data from b2b units t...

  • EPSS 0.18%
  • Veröffentlicht 11.05.2021 15:15:08
  • Zuletzt bearbeitet 21.11.2024 05:58:18

SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the user can iteratively enter on...

  • EPSS 1.9%
  • Veröffentlicht 13.04.2021 19:15:15
  • Zuletzt bearbeitet 21.11.2024 05:58:16

SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker with this a...

  • EPSS 0.99%
  • Veröffentlicht 09.02.2021 21:15:13
  • Zuletzt bearbeitet 21.11.2024 05:48:27

SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed ...

  • EPSS 0.4%
  • Veröffentlicht 09.09.2020 13:15:11
  • Zuletzt bearbeitet 21.11.2024 05:35:28

SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get acces...

  • EPSS 0.32%
  • Veröffentlicht 10.06.2020 13:15:18
  • Zuletzt bearbeitet 21.11.2024 05:35:24

SAP Commerce, versions - 6.7, 1808, 1811, 1905, may allow an attacker to access information under certain conditions which would otherwise be restricted, leading to Information Disclosure.

  • EPSS 0.6%
  • Veröffentlicht 09.06.2020 19:15:10
  • Zuletzt bearbeitet 21.11.2024 05:35:24

SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization that has been configured by the system administrator due to the use of...