PT-2025-10680 · Sap · Sap Commerce

Published

2025-03-11

·

Updated

2025-04-01

·

CVE-2025-27434

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP Commerce (affected versions not specified)
Description The issue is caused by insufficient input validation in SAP Commerce (Swagger UI), allowing an unauthenticated attacker to inject malicious code from remote sources. This can be leveraged to execute a cross-site scripting (XSS) attack, potentially leading to a high impact on data confidentiality, integrity, and availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-03998
CVE-2025-27434

Affected Products

Sap Commerce