CVE Vulnerabilities

CVE-2024-41733

Published: Aug 13, 2024 | Modified: Sep 12, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability

Affected Software

Name Vendor Start Version End Version
Commerce Sap com_cloud_2211 (including) com_cloud_2211 (including)
Commerce Sap hy_com_2205 (including) hy_com_2205 (including)

References