CVE-2018-2463: SSRF
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6., is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side implementation of OCC.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2463?
CVE-2018-2463 has been classified as a high severity vulnerability due to its potential for server-side request forgery attacks.
How do I fix CVE-2018-2463?
To fix CVE-2018-2463, you should apply the latest security patches provided by SAP for the affected versions of Hybris Commerce.
Which versions of SAP Hybris Commerce are affected by CVE-2018-2463?
CVE-2018-2463 affects SAP Hybris Commerce versions 6.0 to 6.7.
What kind of attacks can CVE-2018-2463 lead to?
CVE-2018-2463 can lead to server-side request forgery (SSRF) attacks, allowing unauthorized access to internal resources.
What is the cause of the vulnerability in CVE-2018-2463?
The vulnerability in CVE-2018-2463 is due to a misconfiguration of the XML parser used in the server-side implementation of the Omni Commerce Connect API.