PT-2025-15365 · Sap · Sap Commerce Cloud
Published
2025-04-08
·
Updated
2025-04-09
·
CVE-2025-26654
CVSS v3.1
6.8
Medium
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP Commerce Cloud (affected versions not specified)
Description:
The issue affects the confidentiality and integrity of data sent in the first request before a redirect from HTTP to HTTPS. Normally, Commerce communicates securely over HTTPS, but if a client is configured to use HTTP and sends confidential data before the redirect, this data may be impacted.
Recommendations:
For SAP Commerce Cloud, consider configuring clients to use HTTPS directly to avoid sending confidential data over unencrypted HTTP.
As a temporary workaround, restrict the use of HTTP protocol to minimize the risk of exploitation.
Avoid sending confidential data in the first request before the redirect to HTTPS.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Commerce Cloud