CVE-2024-33003
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Aug 13, 2024
Updated: Sep 16, 2024
CWE ID 200
Summary
CVE-2024-33003 is a vulnerability affecting some OCC API endpoints in SAP Commerce Cloud. This issue allows for the inclusion of Personally Identifiable Information (PII), such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, in the request URL as query or path parameters. Successful exploitation of this vulnerability could result in a significant impact on the confidentiality and integrity of the application, posing a serious risk to users' privacy and data security.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SAP Commerce Cloud
Affected Vendors
- SAP SE