CVE Database
/

CVE-2023-42481

Back to search

CVE-2023-42481

Published: Dec 12, 2023

Modified: Sep 28, 2024

PUBLISHED

CVSS v3.1

8.1

HIGH

Description

In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP Commerce Cloud - Composable Storefront is used as storefront, due to weak access controls in place. This leads to a considerable impact on confidentiality and integrity.

VendorProductVersions

SAP_SE

SAP Commerce Cloud

affected
HY_COM 1905
affected
HY_COM 2005
affected
HY_COM2105
affected
HY_COM 2011
affected
HY_COM 2205

+1 more versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now