SB2024121019 - Information disclosure in SAP Commerce Cloud



SB2024121019 - Information disclosure in SAP Commerce Cloud

Published: December 10, 2024

Security Bulletin ID SB2024121019
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Information disclosure (CVE-ID: CVE-2024-47577)

The vulnerability allows a remote user to gain access to potentially sensitive information.

The vulnerability exists due to the application uses HTTP GET protocol when performing search operation and passes client's personal information via URL. An attacker with access to server logs or ability to intercept HTTP Referer header from the search page can gain access to sensitive data.


Remediation

Install update from vendor's website.