In SAP Commerce, valid user accounts can be
identified during the customer registration and login processes. This allows a
potential attacker to learn if a given e-mail is used for an account, but does
not grant access to any customer data beyond this knowledge. The attacker must
already know the e-mail that they wish to test for. The impact on
confidentiality therefore is low and no impact to integrity or availability
identified during the customer registration and login processes. This allows a
potential attacker to learn if a given e-mail is used for an account, but does
not grant access to any customer data beyond this knowledge. The attacker must
already know the e-mail that they wish to test for. The impact on
confidentiality therefore is low and no impact to integrity or availability
Metrics
Affected Vendors & Products
References
History
Thu, 12 Sep 2024 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap commerce
|
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:sap:commerce:com_cloud_2211:*:*:*:*:*:*:* cpe:2.3:a:sap:commerce:hy_com_2205:*:*:*:*:*:*:* |
|
Vendors & Products |
Sap commerce
|
Tue, 13 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sap
Sap commerce Cloud Sap commerce Hycom |
|
CPEs | cpe:2.3:a:sap:commerce_cloud:2211:*:*:*:*:*:*:* cpe:2.3:a:sap:commerce_hycom:2205:*:*:*:*:*:*:* |
|
Vendors & Products |
Sap
Sap commerce Cloud Sap commerce Hycom |
|
Metrics |
ssvc
|
Tue, 13 Aug 2024 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability | |
Title | Information Disclosure Vulnerability in SAP Commerce | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-13T14:48:19.091Z
Reserved: 2024-07-22T08:06:52.676Z
Link: CVE-2024-41733

Updated: 2024-08-13T14:47:54.137Z

Status : Analyzed
Published: 2024-08-13T04:15:08.987
Modified: 2024-09-12T13:55:49.880
Link: CVE-2024-41733

No data.

No data.