CVE-2023-42481 describes a critical vulnerability in SAP Commerce Cloud (versions HY_COM 1905, 2005, 2105, 2011, 2205, and COM_CLOUD 2211) where a locked B2B user can bypass account restrictions by exploiting the forgotten password functionality when using Composable Storefront. This flaw, stemming from weak access controls (CWE-640), allows the user to regain access, leading to a high impact on confidentiality and integrity. The vulnerability carries a CVSS score of 8.1 (High), indicating it can be exploited remotely with low privileges and complexity, without user interaction. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.1CPE matchmatch criteria | cpe:2.3:a:sap:commerce_cloud:8.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.