SAP
SAP Commerce Cloud: vulnerabilidades y CVE
SAP Commerce Cloud tiene 24 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 7 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE24
Últimos 12 meses6
Críticas7
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-0344 | Crítica (9.8) | 7.1% | ⚠ Explotación activa | 14 ago 2019 | Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights,… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-58231 | Crítica (10) | 0.85% | — | 11 ago 2026 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable… |
| CVE-2026-44761 | Crítica (9.1) | 0.50% | — | 14 jul 2026 | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated… |
| CVE-2026-34263 | Crítica (9.6) | 0.62% | — | 12 may 2026 | Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on… |
| CVE-2026-24321 | Media (5.3) | 0.23% | — | 10 feb 2026 | SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via… |
| CVE-2026-23684 | Media (5.9) | 0.17% | — | 10 feb 2026 | A race condition vulnerability exists in the SAP Commerce cloud. Because of this when an attacker adds products to a cart, it may result in a cart entry being created with erroneous product value which could be checked… |
| CVE-2025-42906 | Media (5.3) | 0.43% | — | 14 oct 2025 | SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed.… |
| CVE-2025-26654 | Media (6.8) | 0.17% | — | 8 abr 2025 | SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over… |
| CVE-2024-47577 | Baja (2.7) | 0.20% | — | 10 dic 2024 | Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes… |
| CVE-2024-33003 | Crítica (9.1) | 0.47% | — | 13 ago 2024 | Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL… |
| CVE-2023-42481 | Alta (8.1) | 0.52% | — | 12 dic 2023 | In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and… |
| CVE-2023-39439 | Crítica (9.8) | 0.71% | — | 8 ago 2023 | SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase. |
| CVE-2023-37486 | Alta (7.5) | 0.52% | — | 8 ago 2023 | Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access information which would otherwise be restricted. On successful exploitation… |
| CVE-2021-33666 | Media (6.1) | 0.54% | — | 9 jun 2021 | When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or malware proliferation. |
| CVE-2021-21445 | Media (5.4) | 0.64% | — | 12 ene 2021 | SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web… |
| CVE-2020-26809 | Media (5.3) | 2.1% | — | 10 nov 2020 | SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could… |
| CVE-2020-6363 | Media (4.6) | 0.53% | — | 15 oct 2020 | SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase… |
| CVE-2020-6272 | Media (5.4) | 0.54% | — | 15 oct 2020 | SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components.… |
| CVE-2020-6238 | Crítica (9.3) | 1.3% | — | 14 abr 2020 | SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability… |
| CVE-2020-6232 | Media (5.3) | 0.83% | — | 14 abr 2020 | SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media. |
| CVE-2020-6201 | Media (6.1) | 0.80% | — | 10 mar 2020 | The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without… |
| CVE-2020-6200 | Media (5.4) | 0.54% | — | 10 mar 2020 | The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the… |
| CVE-2019-0344 | Crítica (9.8) | 7.1% | ⚠ Explotación activa | 14 ago 2019 | Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights,… |
| CVE-2019-0343 | Alta (8.8) | 1.5% | — | 14 ago 2019 | SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code… |
| CVE-2019-0322 | Alta (7.5) | 2.6% | — | 10 jul 2019 | SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de SAP
3D Visual Enterprise Viewer · 131Netweaver · 119Netweaver Application Server Abap · 110Businessobjects Business Intelligence Platform · 80Netweaver Application Server Java · 79S/4hana · 50Businessobjects Business Intelligence · 46Hana · 39Solution Manager · 37Business ONE · 35Abap Platform · 32Netweaver Enterprise Portal · 29