Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7m3q-23p4-mw4v

Опубликовано: 13 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.

EPSS

Процентиль: 73%
0.00747
Низкий

7.4 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.4
nvd
больше 1 года назад

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.

CVSS3: 9.1
fstec
больше 1 года назад

Уязвимость компонента OCC API Endpoint платформ электронной коммерции SAP Commerce Cloud, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации или оказать воздействие на целостность данных

EPSS

Процентиль: 73%
0.00747
Низкий

7.4 High

CVSS3

Дефекты

CWE-200