Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NSap Commerce Cloud
APPSap181119052005201121052205com_cloud_2211hy_com_1808
Related vulnerabilities
RCE przez niebezpieczną deserializację w SAP Commerce Cloud (virtualjdbc)
SAP Commerce Cloud — brak walidacji XML w REST API (XXE)
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 221...
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to...
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authe...