Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with Hybris user rights, resulting in Code Injection.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Commerce_cloud | Sap | 6.4 (including) | 6.4 (including) |
Commerce_cloud | Sap | 6.5 (including) | 6.5 (including) |
Commerce_cloud | Sap | 6.6 (including) | 6.6 (including) |
Commerce_cloud | Sap | 6.7 (including) | 6.7 (including) |
Commerce_cloud | Sap | 1808 (including) | 1808 (including) |
Commerce_cloud | Sap | 1811 (including) | 1811 (including) |
Commerce_cloud | Sap | 1905 (including) | 1905 (including) |