Known Vulnerabilities for Hybris by Sap
Listed below are 8 of the newest known vulnerabilities associated with "Hybris" by "Sap".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-0238 json | SAP Commerce (previously known as SAP Hybris Commerce), before version 6.7, does not sufficiently encode user-controlled inpu... | 6.1 - MEDIUM | 2019-01-08 | 2019-01-17 |
| CVE-2018-2505 json | SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in ... | 6.1 - MEDIUM | 2018-12-11 | 2019-01-07 |
| CVE-2018-2463 json | The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF)... | 8.6 - HIGH | 2018-09-11 | 2018-11-29 |
| CVE-2016-6859 json | Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to obtain sensitive information by triggerin... | 4.3 - MEDIUM | 2016-12-31 | 2017-01-04 |
| CVE-2016-6858 json | Cross-site scripting (XSS) vulnerability in the Create Employee feature in Hybris Management Console (HMC) in SAP Hybris befo... | 5.4 - MEDIUM | 2016-12-31 | 2019-08-27 |
| CVE-2016-6857 json | Cross-site scripting (XSS) vulnerability in the Create Catalogue feature in Hybris Management Console (HMC) in SAP Hybris bef... | 5.4 - MEDIUM | 2016-12-31 | 2019-03-07 |
| CVE-2016-6856 json | Cross-site scripting (XSS) vulnerability in the Inbox Search feature in Hybris Management Console (HMC) in SAP Hybris before ... | 6.1 - MEDIUM | 2016-12-31 | 2017-08-24 |
| CVE-2014-8871 json | Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and ear... | 7.5 - HIGH | 2017-08-28 | 2019-08-27 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Hybris | 6.7 | |||
| Application | Sap | Hybris | 6.6 | |||
| Application | Sap | Hybris | 6.5 | |||
| Application | Sap | Hybris | 6.4 | |||
| Application | Sap | Hybris | 6.3 | |||
| Application | Sap | Hybris | 6.2 | |||
| Application | Sap | Hybris | 6.1 | |||
| Application | Sap | Hybris | 6.0 | |||
| Application | Sap | Hybris | 5.7.0.9 | |||
| Application | Sap | Hybris | 5.7.0.8 | |||
| Application | Sap | Hybris | 5.7.0.15 | |||
| Application | Sap | Hybris | 5.7.0.14 | |||
| Application | Sap | Hybris | 5.7.0 | |||
| Application | Sap | Hybris | 5.6.0.8 | |||
| Application | Sap | Hybris | 5.6.0.7 | |||
| Application | Sap | Hybris | 5.6.0.11 | |||
| Application | Sap | Hybris | 5.6.0.10 | |||
| Application | Sap | Hybris | 5.6.0 | |||
| Application | Sap | Hybris | 5.5.1.9 | |||
| Application | Sap | Hybris | 5.5.1.11 |