CVE-2024-41733

CVSS V2 None CVSS V3 None
Description
In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability
Overview
  • CVE ID
  • CVE-2024-41733
  • Assigner
  • sap
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-08-13T03:52:25.523Z
  • Last Modified Date
  • 2024-08-13T03:52:25.523Z
History
Created Old Value New Value Data Type Notes
2024-08-13 13:04:46 Added to TrackCVE