SAP Commerce Cloud
cpe:2.3:a:sap:commerce_cloud:*:*:*:*:*:*:*
A vulnerability exists in SAP Commerce Cloud, where multiple API endpoints are exposed to unauthenticated users. This allows them to send requests to these open endpoints and retrieve sensitive information that should not be publicly accessible through the front-end. The vulnerability has a low impact on confidentiality and does not affect integrity or availability.
Exploitation of this vulnerability could lead to unauthorized access to sensitive information via the exposed API endpoints.
Users are advised to consult the SAP Security Notes for guidance on addressing this vulnerability. SAP Security Notes can be accessed through the SAP for Me platform.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.