PT-2022-25727 · Sap · Sap Commerce
Published
2022-10-11
·
Updated
2025-05-20
·
CVE-2022-41204
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Commerce versions 1905 through 2205
Description
An attacker can change the content of the SAP Commerce login page through a manipulated URL, allowing them to inject code that redirects submissions from the affected login form to their own server. This enables them to steal credentials and hijack accounts, potentially compromising the Confidentiality, Integrity, and Availability of the system.
Recommendations
For versions 1905 through 2205, consider restricting access to the login page until a fix is available, and avoid using manipulated URLs to prevent code injection. As a temporary workaround, consider disabling the login form submission functionality until a patch is available.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Commerce