PT-2025-41839 · Sap · Sap Commerce Cloud

Published

2025-10-14

·

Updated

2025-10-14

·

CVE-2025-42906

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Commerce Cloud (affected versions not specified)
Description SAP Commerce Cloud contains a path traversal issue that could allow users to access web applications, such as the Administration Console, from locations where it is not explicitly deployed. This may bypass configured access restrictions. The impact on confidentiality is considered low, with no impact on integrity or availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-42906

Affected Products

Sap Commerce Cloud