CVE Database
/

CVE-2018-2505

Back to search

CVE-2018-2505

Published: Dec 11, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are based on the product. Fixed in versions (SAP Hybris Commerce, versions 6.2, 6.3, 6.4, 6.5, 6.6, 6.7).

VendorProductVersions

SAP

SAP Commerce (SAP Hybris Commerce)

affected
6.2
affected
6.3
affected
6.4
affected
6.5
affected
6.6

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now