Home
MEDIUM: 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:NDefault status
unaffected
HY_COM 2205
affected
COM_CLOUD 2211
affected
Description
Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application.
Problem types
CWE-862: Missing Authorization
Product status
HY_COM 2205
COM_CLOUD 2211