First published: Tue Aug 13 2024(Updated: )
In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Commerce | =com_cloud_2211 | |
SAP Commerce | =hy_com_2205 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.