SAP Commerce Cloud是德国思爱普(SAP)公司的一套基于云的电子商务平台。该产支持销售管理、营销管理、订单管理和运营管理等。 SAP Commerce Cloud存在安全漏洞,该漏洞源于辅助服务模块的 Webservice API 端点存在信息泄露漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Commerce Cloud | HY_COM 2205 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-47578 | 9.1 CRITICAL | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) |
| CVE-2024-54198 | 8.5 HIGH | Information Disclosure vulnerability through Remote Function Call (RFC) in SAP NetWeaver A |
| CVE-2024-54197 | 7.2 HIGH | Server-Side Request Forgery in SAP NetWeaver Administrator (System Overview) |
| CVE-2024-47580 | 6.8 MEDIUM | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) |
| CVE-2024-47579 | 6.8 MEDIUM | Multiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services) |
| CVE-2024-47582 | 5.3 MEDIUM | XML Entity Expansion Vulnerability in SAP NetWeaver AS JAVA |
| CVE-2024-32732 | 5.3 MEDIUM | Information Disclosure vulnerability in SAP BusinessObjects Business Intelligence platform |
| CVE-2024-47585 | 4.3 MEDIUM | Missing Authorization check in SAP NetWeaver Application Server for ABAP and ABAP Platform |
| CVE-2024-47581 | 4.3 MEDIUM | Missing Authorization check in SAP HCM (Approve Timesheets version 4) |
| CVE-2024-47576 | 3.3 LOW | DLL Hijacking vulnerability in SAP Product Lifecycle Costing |
No comments yet