PT-2025-15365 · Sap · Sap Commerce Cloud

Published

2025-04-08

·

Updated

2025-04-09

·

CVE-2025-26654

CVSS v3.1

6.8

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: SAP Commerce Cloud (affected versions not specified)
Description: The issue affects the confidentiality and integrity of data sent in the first request before a redirect from HTTP to HTTPS. Normally, Commerce communicates securely over HTTPS, but if a client is configured to use HTTP and sends confidential data before the redirect, this data may be impacted.
Recommendations: For SAP Commerce Cloud, consider configuring clients to use HTTPS directly to avoid sending confidential data over unencrypted HTTP. As a temporary workaround, restrict the use of HTTP protocol to minimize the risk of exploitation. Avoid sending confidential data in the first request before the redirect to HTTPS.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-04846
CVE-2025-26654

Affected Products

Sap Commerce Cloud