Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sap commerce 2005 vulnerabilities and exploits
(subscribe to this query)
6.8
CVSSv2
CVE-2021-42064
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows malicious user to execute crafted database queries, exposing backend database. T...
Sap Commerce 1905
Sap Commerce 2005
Sap Commerce 2011
Sap Commerce 2105
9
CVSSv2
CVE-2021-21477
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution...
Sap Commerce 1808
Sap Commerce 1811
Sap Commerce 1905
Sap Commerce 2005
Sap Commerce 2011
1 Article
4
CVSSv2
CVE-2021-27619
SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the user can iteratively enter one character at a time to searc...
Sap Commerce 1808
Sap Commerce 1811
Sap Commerce 1905
Sap Commerce 2005
Sap Commerce 2011
NA
CVE-2022-41204
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentia...
Sap Commerce 1905
Sap Commerce 2005
Sap Commerce 2011
Sap Commerce 2105
Sap Commerce 2205
1 Article
7.5
CVSSv2
CVE-2020-6302
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, lead...
Sap Commerce 6.7
Sap Commerce 1808
Sap Commerce 1811
Sap Commerce 1905
Sap Commerce 2005
5
CVSSv2
CVE-2020-26809
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an malicious user to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclos...
Sap Commerce Cloud 1808
Sap Commerce Cloud 1811
Sap Commerce Cloud 1905
Sap Commerce Cloud 2005
3.5
CVSSv2
CVE-2020-6272
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later triggered, if an affected web page...
Sap Commerce Cloud 1808
Sap Commerce Cloud 1811
Sap Commerce Cloud 1905
Sap Commerce Cloud 2005
4.9
CVSSv2
CVE-2020-6363
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change their own passphrase, but this doe...
Sap Commerce Cloud 1808
Sap Commerce Cloud 1811
Sap Commerce Cloud 1905
Sap Commerce Cloud 2005
3.5
CVSSv2
CVE-2021-21445
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated malicious user to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may ...
Sap Commerce Cloud 1808
Sap Commerce Cloud 1811
Sap Commerce Cloud 1905
Sap Commerce Cloud 2005
Sap Commerce Cloud 2011
NA
CVE-2022-41266
Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an malicious user to execute a DOM Cross-Site Scripting (XSS) attack. As a result...
Sap Commerce Webservices 2.0 1905
Sap Commerce Webservices 2.0 2005
Sap Commerce Webservices 2.0 2105
Sap Commerce Webservices 2.0 2011
Sap Commerce Webservices 2.0 2205
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7028
memory leak
log injection
CVE-2024-3400
CVE-2022-48695
CVE-2022-48675
CVE-2024-34487
CVE-2024-33792
spoof
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »