Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NDefault status
unaffected
HY_COM 2205
affected
COM_CLOUD 2211
affected
2211-JDK21
affected
Description
SAP Commerce Cloud exposes multiple API endpoints to unauthenticated users, allowing them to submit requests to these open endpoints to retrieve sensitive information that is not intended to be publicly accessible via the front-end. This vulnerability has a low impact on confidentiality and does not affect integrity and availability.
Problem types
CWE-359: Exposure of Private Personal Information to an Unauthorized Actor
Product status
HY_COM 2205
COM_CLOUD 2211
2211-JDK21