cbcvebase.
CVE-2024-47577
published 2024-12-10

CVE-2024-47577: Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for…

PriorityP49low2.7CVSS 3.1
AVNACLPRHUINSUCLINAN
EPSS
0.20%
9.5th percentile
Webservice API endpoints for Assisted Service Module within SAP Commerce Cloud has information disclosure vulnerability. When an authorized agent searches for customer to manage their accounts, the request url includes customer data and it is recorded in server logs. If an attacker impersonating as authorized admin visits such server logs, then they get access to the customer data. The amount of leaked confidential data however is extremely limited, and the attacker has no control over what data is leaked.

Affected

2 ranges
VendorProductVersion rangeFixed in
sap_sesap_commerce_cloud
sap_sesap_commerce_cloud
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.