Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4x4m-ghmx-6q9w

Опубликовано: 13 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability

EPSS

Процентиль: 67%
0.0053
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5.3
nvd
больше 1 года назад

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability

CVSS3: 5.3
fstec
больше 1 года назад

Уязвимость платформы электронной коммерции SAP Commerce Cloud, связанная с недостаточной защитой служебных данных, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 67%
0.0053
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-200