SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.
Using an empty string as a password is insecure.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Commerce_cloud | Sap | 2211 (including) | 2211 (including) |
| Commerce_hycom | Sap | 2105 (including) | 2105 (including) |
| Commerce_hycom | Sap | 2205 (including) | 2205 (including) |