CVE-2023-39439 is a critical vulnerability affecting SAP Commerce Cloud and SAP Commerce Hybris, allowing attackers to log in with an empty passphrase for user ID and passphrase authentication. With a CVSS score of 9.8, this flaw permits unauthenticated remote attackers to achieve full compromise (confidentiality, integrity, availability) with low attack complexity. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion, indicating awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2211CPE matchmatch criteria | cpe:2.3:a:sap:commerce_cloud:2211:*:*:*:*:*:*:* | ||
2105CPE matchmatch criteria | cpe:2.3:a:sap:commerce_hycom:2105:*:*:*:*:*:*:* | ||
2205CPE matchmatch criteria | cpe:2.3:a:sap:commerce_hycom:2205:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.