SAP Commerce Cloud是德国SAP公司的一套基于云的电子商务平台。该产支持销售管理、营销管理、订单管理和运营管理等。 SAP Commerce Cloud COM_CLOUD 2211版本和2211-JDK21版本存在代码注入漏洞,该漏洞源于未经身份验证的攻击者滥用默认身份验证客户端,并向某些功能提交缺乏充分验证的特制输入,可能导致任意代码执行并危害内部组件,对机密性、完整性和可用性造成高影响。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP_SE | SAP Commerce Cloud (Data Hub Adapter) | COM_CLOUD 2211 |
affected |
2211-JDK21 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SAP_SE | SAP Commerce Cloud (Data Hub Adapter) | COM_CLOUD 2211 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34265 | 9.8 CRITICAL | Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Plat |
| CVE-2026-44758 | 9.1 CRITICAL | Code Injection vulnerability in Manufacturing Integration and Intelligence |
| CVE-2026-58243 | 8.8 HIGH | Privilege Escalation vulnerability in SAP ABAP Developer Tools |
| CVE-2026-66763 | 7.9 HIGH | Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Mana |
| CVE-2026-44763 | 7.6 HIGH | Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence |
| CVE-2026-44764 | 7.3 HIGH | Missing Authorization Check in SAP Manufacturing Integration and Intelligence |
| CVE-2026-44765 | 7.3 HIGH | Missing Authorization Check in SAP Manufacturing Integration and Intelligence |
| CVE-2026-58230 | 7.0 HIGH | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-58248 | 6.5 MEDIUM | XML External Entity Injection in SAP BusinessObjects Business Intelligence |
| CVE-2026-66760 | 6.4 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-66779 | 6.3 MEDIUM | Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP |
| CVE-2026-66770 | 6.3 MEDIUM | SQL Injection vulnerability in SAP Social Intelligence |
| CVE-2026-58235 | 6.3 MEDIUM | Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services) |
| CVE-2026-66771 | 6.1 MEDIUM | Cross Site Scripting (XSS) vulnerability in SAPUI5 |
| CVE-2026-58238 | 5.9 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-66773 | 5.9 MEDIUM | Server-controlled `__next` URL is not checking cross-origin |
| CVE-2026-58237 | 5.9 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-66777 | 5.9 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-66776 | 5.9 MEDIUM | Multiple vulnerabilities in SAP Business AI Platform (Approuter) |
| CVE-2026-58236 | 5.5 MEDIUM | OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Pl |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet