Description
In SAP Commerce, valid user accounts can be
identified during the customer registration and login processes. This allows a
potential attacker to learn if a given e-mail is used for an account, but does
not grant access to any customer data beyond this knowledge. The attacker must
already know the e-mail that they wish to test for. The impact on
confidentiality therefore is low and no impact to integrity or availability
identified during the customer registration and login processes. This allows a
potential attacker to learn if a given e-mail is used for an account, but does
not grant access to any customer data beyond this knowledge. The attacker must
already know the e-mail that they wish to test for. The impact on
confidentiality therefore is low and no impact to integrity or availability
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39176 | In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability |
References
History
Thu, 12 Sep 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap commerce
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:sap:commerce:com_cloud_2211:*:*:*:*:*:*:* cpe:2.3:a:sap:commerce:hy_com_2205:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap commerce
|
Tue, 13 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap commerce Cloud Sap commerce Hycom |
|
| CPEs | cpe:2.3:a:sap:commerce_cloud:2211:*:*:*:*:*:*:* cpe:2.3:a:sap:commerce_hycom:2205:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap commerce Cloud Sap commerce Hycom |
|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability | |
| Title | Information Disclosure Vulnerability in SAP Commerce | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-13T14:48:19.091Z
Reserved: 2024-07-22T08:06:52.676Z
Link: CVE-2024-41733
Updated: 2024-08-13T14:47:54.137Z
Status : Analyzed
Published: 2024-08-13T04:15:08.987
Modified: 2024-09-12T13:55:49.880
Link: CVE-2024-41733
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD