CVE Database
/

CVE-2022-41204

Back to search

CVE-2022-41204

Published: Oct 11, 2022

Modified: May 20, 2025

PUBLISHED

Description

An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentials and hijack accounts. A successful attack could compromise the Confidentiality, Integrity, and Availability of the system.

VendorProductVersions

SAP SE

SAP Commerce

affected
1905
affected
2005
affected
2105
affected
2011
affected
2205

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now