CVE-2023-37486: Information Disclosure vulnerability in SAP Commerce (OCC API)
Published Aug 8, 2023
·Updated
Under certain conditions SAP Commerce (OCC API) - versions HYCOM 2105, HYCOM 2205, COMCLOUD 2211, endpoints allow an attacker to access information which would otherwise be restricted. On successful exploitation there could be a high impact on confidentiality with no impact on integrity and availability of the application.
Affected Software
3 affected components
SAP Commerce Cloud=2211
SAP Commerce Hycom=2105
SAP Commerce Hycom=2205
Event History
Aug 8, 2023
CVE Published
via MITRE·12:56 AM
Data Sourced
via MITRE·12:56 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this SAP Commerce (OCC API) vulnerability?
The vulnerability ID is CVE-2023-37486.
2
What is the severity of CVE-2023-37486?
The severity of CVE-2023-37486 is high with a severity value of 7.5.
3
What software versions are affected by CVE-2023-37486?
The affected software versions are HY_COM 2105, HY_COM 2205, and COM_CLOUD 2211.
4
What is the impact of the vulnerability CVE-2023-37486?
The vulnerability could have a high impact on confidentiality with no impact on integrity and availability.
5
How can I fix the SAP Commerce (OCC API) vulnerability CVE-2023-37486?
To fix the vulnerability, apply the necessary patches and updates provided by SAP.