VYPR

Commerce

by SAP

CVEs (27)

  • CVE-2024-45278MedOct 8, 2024
    risk 0.35cvss 5.4epss 0.00

    SAP Commerce Backoffice does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. After successful exploitation, an attacker can cause limited impact on confidentiality and integrity of the application.

  • CVE-2024-41735MedAug 13, 2024
    risk 0.35cvss 5.4epss 0.00

    SAP Commerce Backoffice does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability causing low impact on confidentiality and integrity of the application.

  • CVE-2020-26811MedNov 10, 2020
    risk 0.35cvss 5.3epss 0.02

    SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads…

  • CVE-2020-6232MedApr 14, 2020
    risk 0.35cvss 5.3epss 0.01

    SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.

  • CVE-2020-6200MedMar 10, 2020
    risk 0.35cvss 5.4epss 0.01

    The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.

  • CVE-2024-41733MedAug 13, 2024
    risk 0.34cvss 5.3epss 0.00

    In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker…

  • CVE-2025-27435MedApr 8, 2025
    risk 0.27cvss 4.2epss 0.00

    Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on…

Page 2 of 2