OCC API Endpoints Vulnerable to PII Data Exposure
CVE-2024-33003
Summary
A vulnerability has been identified in certain OCC API endpoints of SAP Commerce Cloud, which allows for the exposure of Personally Identifiable Information (PII). This issue occurs when sensitive data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, is included directly in the request URL, either as query or path parameters. The compromised integrity and confidentiality of this information can have serious repercussions, making it crucial for organizations using affected versions to assess their security posture. To mitigate the risks associated with this vulnerability, users are advised to apply the appropriate security patches and review their API endpoint configurations.
Affected Version(s)
SAP Commerce Cloud HY_COM 1808
SAP Commerce Cloud 1811
SAP Commerce Cloud 1905
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved