Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpv9-9vrq-v7c4

Опубликовано: 10 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-359

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 месяцев назад

SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.

EPSS

Процентиль: 16%
0.00052
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-359