CVE-2025-27434
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Mar 11, 2025
CWE ID 79
Summary
CVE-2025-27434 is a vulnerability affecting SAP Commerce's Swagger UI. The issue stems from inadequate input validation, allowing unauthenticated attackers to insert malicious code from external sources. This vulnerability can be exploited through cross-site scripting (XSS) attacks, posing a significant threat to the confidentiality, integrity, and availability of data in SAP Commerce. Successful exploitation could lead to data theft, unauthorized system access, or denial-of-service incidents.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SAP Commerce
Affected Vendors
- SAP SE