In SAP Commerce, valid user accounts can be
identified during the customer registration and login processes. This allows a
potential attacker to learn if a given e-mail is used for an account, but does
not grant access to any customer data beyond this knowledge. The attacker must
already know the e-mail that they wish to test for. The impact on
confidentiality therefore is low and no impact to integrity or availability
identified during the customer registration and login processes. This allows a
potential attacker to learn if a given e-mail is used for an account, but does
not grant access to any customer data beyond this knowledge. The attacker must
already know the e-mail that they wish to test for. The impact on
confidentiality therefore is low and no impact to integrity or availability
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-39176 | In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 12 Sep 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap commerce
|
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:sap:commerce:com_cloud_2211:*:*:*:*:*:*:* cpe:2.3:a:sap:commerce:hy_com_2205:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap commerce
|
Tue, 13 Aug 2024 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap commerce Cloud Sap commerce Hycom |
|
| CPEs | cpe:2.3:a:sap:commerce_cloud:2211:*:*:*:*:*:*:* cpe:2.3:a:sap:commerce_hycom:2205:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sap
Sap commerce Cloud Sap commerce Hycom |
|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability | |
| Title | Information Disclosure Vulnerability in SAP Commerce | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-13T14:48:19.091Z
Reserved: 2024-07-22T08:06:52.676Z
Link: CVE-2024-41733
Updated: 2024-08-13T14:47:54.137Z
Status : Analyzed
Published: 2024-08-13T04:15:08.987
Modified: 2024-09-12T13:55:49.880
Link: CVE-2024-41733
No data.
OpenCVE Enrichment
No data.
EUVD