CVE-2025-26654
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Apr 8, 2025
CWE ID 319
Summary
CVE-2025-26654: SAP Commerce Cloud (Public Cloud) does not completely disable unencrypted HTTP connections, instead offering a redirect from port 80 to 443. While this typically ensures secure communication via HTTPS, data confidentiality and integrity during the initial HTTP request before the redirect may be compromised if clients transmit confidential information using HTTP.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SAP Commerce Cloud
Affected Vendors
- SAP SE