Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
sap commerce 2005 vulnerabilities and exploits
(subscribe to this query)
8.1
CVSSv3
CVE-2023-42481
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP Commerce Cloud - Composable Storefront i...
Sap Commerce Cloud 8.1
6.1
CVSSv3
CVE-2022-41266
Due to a lack of proper input validation, SAP Commerce Webservices 2.0 (Swagger UI) - versions 1905, 2005, 2105, 2011, 2205, allows malicious inputs from untrusted sources, which can be leveraged by an malicious user to execute a DOM Cross-Site Scripting (XSS) attack. As a result...
Sap Commerce Webservices 2.0 1905
Sap Commerce Webservices 2.0 2005
Sap Commerce Webservices 2.0 2105
Sap Commerce Webservices 2.0 2011
Sap Commerce Webservices 2.0 2205
8.8
CVSSv3
CVE-2022-41204
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentia...
Sap Commerce 1905
Sap Commerce 2005
Sap Commerce 2011
Sap Commerce 2105
Sap Commerce 2205
1 Article
9.8
CVSSv3
CVE-2021-42064
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows malicious user to execute crafted database queries, exposing backend database. T...
Sap Commerce 1905
Sap Commerce 2005
Sap Commerce 2011
Sap Commerce 2105
6.5
CVSSv3
CVE-2021-27619
SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the user can iteratively enter one character at a time to searc...
Sap Commerce 1808
Sap Commerce 1811
Sap Commerce 1905
Sap Commerce 2005
Sap Commerce 2011
9.9
CVSSv3
CVE-2021-27602
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker with this authorization can inject malici...
Sap Commerce 1808
Sap Commerce 1811
Sap Commerce 1905
Sap Commerce 2005
Sap Commerce 2011
2 Articles
9.9
CVSSv3
CVE-2021-21477
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution...
Sap Commerce 1808
Sap Commerce 1811
Sap Commerce 1905
Sap Commerce 2005
Sap Commerce 2011
1 Article
5.4
CVSSv3
CVE-2021-21445
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated malicious user to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may ...
Sap Commerce Cloud 1808
Sap Commerce Cloud 1811
Sap Commerce Cloud 1905
Sap Commerce Cloud 2005
Sap Commerce Cloud 2011
5.3
CVSSv3
CVE-2020-26809
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an malicious user to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclos...
Sap Commerce Cloud 1808
Sap Commerce Cloud 1811
Sap Commerce Cloud 1905
Sap Commerce Cloud 2005
7.5
CVSSv3
CVE-2020-26810
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated malicious user to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request c...
Sap Commerce Cloud (accelerator Payment Mock) 1808
Sap Commerce Cloud (accelerator Payment Mock) 1811
Sap Commerce Cloud (accelerator Payment Mock) 1905
Sap Commerce Cloud (accelerator Payment Mock) 2005
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »