Vulnerabilities
Vulnerable Software
Sap:  >> Commerce  >> 2105  Security Vulnerabilities
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentials and hijack accounts. A successful attack could compromise the Confidentiality, Integrity, and Availability of the system.
CVSS Score
8.8
EPSS Score
0.004
Published
2022-10-11
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The vulnerability is present if the parameterized "in" clause accepts more than 1000 values.
CVSS Score
9.8
EPSS Score
0.008
Published
2021-12-14


Contact Us

Shodan ® - All rights reserved