CVE-2025-26654

CVSS 3.1 Score 6.8 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 319

Summary

CVE-2025-26654: SAP Commerce Cloud (Public Cloud) does not completely disable unencrypted HTTP connections, instead offering a redirect from port 80 to 443. While this typically ensures secure communication via HTTPS, data confidentiality and integrity during the initial HTTP request before the redirect may be compromised if clients transmit confidential information using HTTP.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share