Commerce

Vendor:

First CVE: Jun 9, 2020 · Active for 6 years

10
Total CVEs
More Total CVEs than 88% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Commerce over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 9, 2020
6 years ago
Most Recent CVE
Aug 13, 2024
710 days ago

CVE Severity & Scoring

Commerce10 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None9 (90.0%)
Unknown0 (0.0%)
Required1 (10.0%)
Privileges Required
Low4 (40.0%)
High0 (0.0%)
None6 (60.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be
Feb 9, 20219.946NONO
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when publis
Apr 13, 20219.930NONO
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 201
Dec 14, 20219.829NONO
SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization
Jun 9, 20209.829NONO
An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redire
Oct 11, 20228.828NONO
SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Authent
Nov 10, 20218.827NONO
SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Alt
May 11, 20216.521NONO
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via s
Sep 9, 20208.120NONO
SAP Commerce, versions - 6.7, 1808, 1811, 1905, may allow an attacker to access information under certain conditions which would otherwise be restricted, leading to Information Dis
Jun 10, 20207.519NONO
In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for
Aug 13, 20245.317NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Commerce

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
hy_com_220515.30.3%00
com_cloud_221115.30.3%00
6.738.51.1%00
220518.80.8%00
2105.318.80.8%00
210529.30.9%00
2011.1318.80.8%00
201159.06.9%00
2005.1818.80.8%00
200568.85.9%00
1905.3418.80.8%00
190588.84.7%00
181168.66.0%00
180868.66.0%00