CVE-2024-41733
In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability
Published:Aug 13, 2024
Last Modified:Sep 12, 2024
EPS:Aug 13, 2024
EPSS Score:0.00141
CVSS Score:5.3
Affected Products
Vendor
Product
Action
Vendor
Sap
Product
Commerce
Sap
Commerce
Vendor
Sap
Product
Commerce Cloud
Sap
Commerce Cloud
Vendor
Sap
Product
Commerce Hycom
Sap
Commerce Hycom
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
