First published: Tue Aug 08 2023(Updated: )
Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access information which would otherwise be restricted. On successful exploitation there could be a high impact on confidentiality with no impact on integrity and availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Commerce | =2211 | |
SAP Commerce | =2105 | |
SAP Commerce | =2205 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-37486.
The severity of CVE-2023-37486 is high with a severity value of 7.5.
The affected software versions are HY_COM 2105, HY_COM 2205, and COM_CLOUD 2211.
The vulnerability could have a high impact on confidentiality with no impact on integrity and availability.
To fix the vulnerability, apply the necessary patches and updates provided by SAP.