VDB

CISA-2024-33003

CISA-2024-33003 PUBLISHED CVSS 7.4 HIGH

Reported by sap · Published August 13, 2024

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.

Risk Scores

CVSS 3.1
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products

VendorProductVersions
SAP_SESAP Commerce CloudHY_COM 1808, 1811, 1905
SAP_SESAP Commerce Cloud2205, 1905, 2005
sapcommerce_cloud1808, 1811, 1905

Timeline

  • Aug 13, 2024 CVE Published
  • Aug 13, 2024 CVE Updated

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›