SAP
SAP Commerce: vulnerabilidades y CVE
SAP Commerce tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-27435 | Media (4.2) | 0.23% | — | 8 abr 2025 | Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use… |
| CVE-2025-27434 | Alta (8.8) | 0.45% | — | 11 mar 2025 | Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site… |
| CVE-2025-24875 | Media (6.8) | 0.18% | — | 11 feb 2025 | SAP Commerce, by default, sets certain cookies with the SameSite attribute configured to None (SameSite=None). This includes authentication cookies utilized in SAP Commerce Backoffice. Applying this setting reduces… |
| CVE-2025-24874 | Media (6.8) | 0.32% | — | 11 feb 2025 | SAP Commerce (Backoffice) uses the deprecated X-FRAME-OPTIONS header to protect against clickjacking. While this protection remains effective now, it may not be the case in the future as browsers might discontinue… |
| CVE-2024-41733 | Media (5.3) | 0.31% | — | 13 ago 2024 | In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access… |
| CVE-2024-39597 | Alta (7.2) | 0.28% | — | 9 jul 2024 | In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and registration is activated, without requiring the merchant to approve… |
| CVE-2022-41204 | Alta (8.8) | 0.83% | — | 11 oct 2022 | An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login… |
| CVE-2021-42064 | Crítica (9.8) | 1.1% | — | 14 dic 2021 | If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted… |
| CVE-2021-40502 | Alta (8.8) | 0.83% | — | 10 nov 2021 | SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Authenticated attackers will be able to access… |
| CVE-2021-27619 | Media (6.5) | 0.82% | — | 11 may 2021 | SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked,… |
| CVE-2021-27602 | Crítica (9.9) | 2.0% | — | 13 abr 2021 | SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the… |
| CVE-2021-21477 | Crítica (9.9) | 30% | — | 9 feb 2021 | SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the… |
| CVE-2020-6302 | Alta (8.1) | 0.80% | — | 9 sept 2020 | SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle… |
| CVE-2020-6264 | Alta (7.5) | 0.97% | — | 10 jun 2020 | SAP Commerce, versions - 6.7, 1808, 1811, 1905, may allow an attacker to access information under certain conditions which would otherwise be restricted, leading to Information Disclosure. |
| CVE-2020-6265 | Crítica (9.8) | 1.4% | — | 9 jun 2020 | SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization that has been configured by the system… |
Otros productos de SAP
3D Visual Enterprise Viewer · 131Netweaver · 119Netweaver Application Server Abap · 110Businessobjects Business Intelligence Platform · 80Netweaver Application Server Java · 79S/4hana · 50Businessobjects Business Intelligence · 46Hana · 39Solution Manager · 37Business ONE · 35Abap Platform · 32Netweaver Enterprise Portal · 29