Known Vulnerabilities for Commerce Cloud by Sap
Listed below are 10 of the newest known vulnerabilities associated with "Commerce Cloud" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2021-33666 | When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circ... | 6.1 - MEDIUM | 2021-06-09 | 2021-06-21 |
| CVE-2021-21445 | SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in ... | 5.4 - MEDIUM | 2021-01-12 | 2021-03-04 |
| CVE-2020-26809 | SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks... | 5.3 - MEDIUM | 2020-11-10 | 2021-06-17 |
| CVE-2020-6363 | SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. T... | 4.6 - MEDIUM | 2020-10-15 | 2020-10-19 |
| CVE-2020-6272 | SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated... | 5.4 - MEDIUM | 2020-10-15 | 2020-10-19 |
| CVE-2020-6238 | SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyforms... | 9.3 - CRITICAL | 2020-04-14 | 2022-10-06 |
| CVE-2020-6232 | SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Auth... | 5.3 - MEDIUM | 2020-04-14 | 2020-04-15 |
| CVE-2020-6201 | The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inpu... | 6.1 - MEDIUM | 2020-03-10 | 2020-03-12 |
| CVE-2020-6200 | The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injec... | 5.4 - MEDIUM | 2020-03-10 | 2020-03-11 |
| CVE-2019-0322 | SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows ... | 7.5 - HIGH | 2019-07-10 | 2020-08-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Commerce Cloud | 6.7 | All | All | All |
| Application | Sap | Commerce Cloud | 6.6 | All | All | All |
| Application | Sap | Commerce Cloud | 6.5 | All | All | All |
| Application | Sap | Commerce Cloud | 6.4 | All | All | All |
| Application | Sap | Commerce Cloud | 6.3 | All | All | All |
| Application | Sap | Commerce Cloud | 2011 | All | All | All |
| Application | Sap | Commerce Cloud | 2005 | All | All | All |
| Application | Sap | Commerce Cloud | 1905 | All | All | All |
| Application | Sap | Commerce Cloud | 1811 | All | All | All |
| Application | Sap | Commerce Cloud | 1808 | All | All | All |