CVE-2022-41204: High severity SAP Commerce vulnerability
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentials and hijack accounts. A successful attack could compromise the Confidentiality, Integrity, and Availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-41204?
CVE-2022-41204 is classified as a critical vulnerability due to the potential for credential theft and account hijacking.
How can I fix CVE-2022-41204?
To mitigate CVE-2022-41204, update to a patched version of SAP Commerce that addresses this vulnerability.
Who is affected by CVE-2022-41204?
CVE-2022-41204 affects users of SAP Commerce versions 1905, 2005, 2105, 2011, and 2205.
What type of attack is associated with CVE-2022-41204?
CVE-2022-41204 is associated with a phishing attack that leverages a manipulated URL to hijack credentials.
What are the consequences of CVE-2022-41204?
The consequences of CVE-2022-41204 include unauthorized access to user accounts and potential data breaches.