CVE-2025-27435: Information Disclosure Vulnerability in SAP Commerce Cloud
Published Apr 8, 2025
·Updated
Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application.
Affected Software
1 affected component
SAP Commerce Cloud
Event History
Apr 8, 2025
CVE Published
via MITRE·07:13 AM
Data Sourced
via MITRE·07:13 AM
DescriptionSeverity
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-27435?
CVE-2025-27435 is classified as a low severity vulnerability.
2
How do I fix CVE-2025-27435?
To fix CVE-2025-27435, update to the latest version of SAP Commerce that addresses this vulnerability.
3
Who is affected by CVE-2025-27435?
SAP Commerce users who implement coupon campaigns are affected by CVE-2025-27435.
4
What is the impact of CVE-2025-27435?
CVE-2025-27435 allows an unauthenticated attacker to access and use exposed customer coupon codes.
5
When was CVE-2025-27435 reported?
CVE-2025-27435 was reported in early 2025.