Impact
SAP Commerce Cloud allows an unauthenticated attacker to exploit a default authentication client and send specially crafted data to functions that lack proper validation. This flaw is a code injection vulnerability (CWE-94) that can lead to arbitrary code execution and compromise the confidentiality, integrity, and availability of internal components.
Affected Systems
The affected product is SAP Commerce Cloud Data Hub Adapter as identified by SAP SE. No specific version numbers are listed in the available data, so all releases using the default authentication client are potentially vulnerable. The SAP Note 3771065 and the SAP Security Patch Day URL provide additional context for affected deployments.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity. Because the EPSS score is not available, the exploitation likelihood is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote and unauthenticated, inferred from the description that the attacker can submit input without prior authentication. Successful exploitation would enable the attacker to run arbitrary code within the application context.
OpenCVE Enrichment