An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentials and hijack accounts. A successful attack could compromise the Confidentiality, Integrity, and Availability of the system.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-44445 An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentials and hijack accounts. A successful attack could compromise the Confidentiality, Integrity, and Availability of the system.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 20 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-05-20T15:07:49.563Z

Reserved: 2022-09-21T00:00:00.000Z

Link: CVE-2022-41204

cve-icon Vulnrichment

Updated: 2024-08-03T12:35:49.564Z

cve-icon NVD

Status : Modified

Published: 2022-10-11T21:15:26.377

Modified: 2025-05-20T16:15:22.673

Link: CVE-2022-41204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.