VYPR
High severity8.8NVD Advisory· Published Aug 8, 2023· Updated Jun 17, 2026

CVE-2023-39439

CVE-2023-39439

Description

SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.

Affected products

5
  • cpe:2.3:a:sap:commerce_cloud:2211:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:commerce_cloud:2211:*:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:a:sap:commerce_hycom:2105:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:commerce_hycom:2105:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:commerce_hycom:2205:*:*:*:*:*:*:*
  • SAP/Commercecpe-rescue
    Range: HY_COM 2105

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.