VDB
CISA-2024-33003
CISA-2024-33003
PUBLISHED
CVSS 7.4 HIGH
Reported by sap · Published August 13, 2024
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.
Risk Scores
CVSS 3.1
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP_SE | SAP Commerce Cloud | HY_COM 1808, 1811, 1905 |
| SAP_SE | SAP Commerce Cloud | 2205, 1905, 2005 |
| sap | commerce_cloud | 1808, 1811, 1905 |
Timeline
- Aug 13, 2024 CVE Published
- Aug 13, 2024 CVE Updated