SB2024121019 - Information disclosure in SAP Commerce Cloud
Published: December 10, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Information disclosure (CVE-ID: CVE-2024-47577)
CWE-ID: CWE-200 - Exposure of sensitive information to an unauthorized actor
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to the application uses HTTP GET protocol when performing search operation and passes client's personal information via URL. An attacker with access to server logs or ability to intercept HTTP Referer header from the search page can gain access to sensitive data.
Remediation
Install update from vendor's website.