Логотип exploitDog
bind:CVE-2025-26654
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-26654

Количество 3

Количество 3

nvd логотип

CVE-2025-26654

10 месяцев назад

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request before the redirect may be impacted if the client is configured to use HTTP and sends confidential data on the first request before the redirect.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-gj2r-xj7g-vp59

10 месяцев назад

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request before the redirect may be impacted if the client is configured to use HTTP and sends confidential data on the first request before the redirect.

CVSS3: 6.8
EPSS: Низкий
fstec логотип

BDU:2025-04846

10 месяцев назад

Уязвимость платформы электронной коммерции SAP Commerce Cloud, связанная с передачей критичной информации открытым текстом, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-26654

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request before the redirect may be impacted if the client is configured to use HTTP and sends confidential data on the first request before the redirect.

CVSS3: 6.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-gj2r-xj7g-vp59

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request before the redirect may be impacted if the client is configured to use HTTP and sends confidential data on the first request before the redirect.

CVSS3: 6.8
0%
Низкий
10 месяцев назад
fstec логотип
BDU:2025-04846

Уязвимость платформы электронной коммерции SAP Commerce Cloud, связанная с передачей критичной информации открытым текстом, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.8
0%
Низкий
10 месяцев назад

Уязвимостей на страницу