Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Apr 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application. | |
| Title | Information Disclosure Vulnerability in SAP Commerce Cloud | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2025-04-08T07:13:49.402Z
Updated: 2025-04-08T13:28:27.656Z
Reserved: 2025-02-25T09:29:51.244Z
Link: CVE-2025-27435
Updated: 2025-04-08T13:28:21.331Z
Status : Awaiting Analysis
Published: 2025-04-08T08:15:16.550
Modified: 2025-04-08T18:13:53.347
Link: CVE-2025-27435
No data.