CVE-2023-39439: SAP Commerce accepts empty passphrases.
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39439?
CVE-2023-39439 is a vulnerability in SAP Commerce Cloud that allows users to log into the system without a passphrase.
How severe is CVE-2023-39439?
CVE-2023-39439 is considered a critical vulnerability with a severity value of 9.8.
Which software versions are affected by CVE-2023-39439?
SAP Commerce Cloud versions 2211, Sap Commerce Hycom versions 2105 and 2205 are affected by CVE-2023-39439.
How can I fix CVE-2023-39439?
To fix CVE-2023-39439, apply the recommended patches and updates provided by SAP.
Where can I find more information about CVE-2023-39439?
You can find more information about CVE-2023-39439 at the following references: [Link 1](https://me.sap.com/notes/3346500), [Link 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html)