Remote Code Injection Vulnerability in SAP Commerce
CVE-2022-41204
8.8HIGH
What is CVE-2022-41204?
This vulnerability in SAP Commerce allows attackers to manipulate the login page through a crafted URL. By injecting malicious code, an attacker can redirect user logins to their own server, enabling the theft of credentials and unauthorized access to accounts. This jeopardizes the confidentiality, integrity, and availability of the affected systems, making it critical for users to ensure their applications are updated and secured.
Affected Version(s)
SAP Commerce 1905
SAP Commerce 2005
SAP Commerce 2105