← voltar
CVE-2024-39597

[CVE-2024-39597] Improper Authorization Checks on Early Login Composable Storefront B2B sites of SAP Commerce

CVSS 7.2 HIGHEPSS 0.3%CWE-285
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 7.2EPSS 0.3%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
09 jul 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
In SAP Commerce, a user can misuse the forgotten password functionality to gain access to a Composable Storefront B2B site for which early login and registration is activated, without requiring the merchant to approve the account beforehand. If the site is not configured as isolated site, this can also grant access to other non-isolated early login sites, even if registration is not enabled for those other sites.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Produtos afetados
SAP_SE · SAP Commerce

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →