SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSap Commerce Cloud
APPSap1808181119056.46.56.66.7
Related vulnerabilities
RCE przez niebezpieczną deserializację w SAP Commerce Cloud (virtualjdbc)
SAP Commerce Cloud — brak walidacji XML w REST API (XXE)
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as pa...
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 221...
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to...