Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7xw7-hxcm-552f

Опубликовано: 14 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.

EPSS

Процентиль: 38%
0.00465
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1392

Связанные уязвимости

CVSS3: 9.1
nvd
19 дней назад

SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.

CVSS3: 9.1
fstec
19 дней назад

Уязвимость платформы электронной коммерции SAP Commerce Cloud, связанная с использованием учетных данных по умолчанию, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 38%
0.00465
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-1392