📦 Commerce Cloud

by Sap

🔍 What is Commerce Cloud?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-33003

HIGH CVSS 7.4 Aug 13, 2024

This vulnerability in SAP Commerce Cloud's OCC API endpoints allows attackers to access sensitive PII data like passwords, email addresses, and coupon codes through URL parameters. It affects organiza...

CVE-2023-42481

HIGH CVSS 8.1 Dec 12, 2023

This vulnerability allows locked B2B users in SAP Commerce Cloud to bypass account restrictions by exploiting the forgotten password functionality when using Composable Storefront. Attackers can regai...

CVE-2026-24321

MEDIUM CVSS 5.3 Feb 10, 2026

SAP Commerce Cloud exposes sensitive API endpoints to unauthenticated users, allowing unauthorized access to confidential information. This affects organizations using vulnerable versions of SAP Comme...

CVE-2026-23684

MEDIUM CVSS 5.9 Feb 10, 2026

A race condition vulnerability in SAP Commerce Cloud allows attackers to manipulate cart entries during product addition, potentially enabling checkout with incorrect product values. This affects data...