Impact
An SAP Commerce Cloud deployment may retain a sample OAuth2 client that contains publicly documented credentials provided in sample configuration documents. An unauthenticated attacker can use these well‑known credentials to acquire a valid access token and then invoke certain APIs to read and modify protected data. The weakness corresponds to misconfiguration (CWE‑1392) and results in a high‑impact compromise of confidentiality and integrity with no effect on availability.
Affected Systems
Any SAP Commerce Cloud installation that has not removed or updated the built‑in sample OAuth2 client configuration is susceptible. The advisory does not list specific product versions, so all releases that still ship this default client when left untouched are at risk.
Risk and Exploitability
The CVSS score of 9.1 classifies the issue as critical, and the EPSS score of < 1 % indicates that exploitation activity is currently low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an adversary with network access to the OAuth2 authorization endpoint; once the default client is used, the token acquisition process is trivial and requires no additional privileges, allowing the attacker to compromise sensitive data within the Commerce application.
OpenCVE Enrichment