Commerce Cloud
Vendor:
First CVE: Jul 10, 2019 · Active for 7 years
18
Total CVEs
More Total CVEs than 93% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
5.6%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Commerce Cloud over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 10, 2019
7 years ago
Most Recent CVE
Feb 10, 2026
164 days ago
CVE Severity & Scoring
Commerce Cloud18 CVEs
56%
22%
22%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required6 (33.3%)
Privileges Required
Low6 (33.3%)
High0 (0.0%)
None12 (66.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-0344CRITICAL Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a targe | Aug 14, 2019 | 9.8 | 73 | YES | NO |
CVE-2023-39439CRITICAL SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase. | Aug 8, 2023 | 9.8 | 30 | NO | NO |
CVE-2024-33003CRITICAL Some OCC API endpoints in SAP Commerce Cloud
allows Personally Identifiable Information (PII) data, such as passwords, email
addresses, mobile numbers, coupon codes, and voucher co | Aug 13, 2024 | 9.1 | 26 | NO | NO |
CVE-2019-0343HIGH SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by th | Aug 14, 2019 | 8.8 | 26 | NO | NO |
CVE-2019-0322HIGH SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing | Jul 10, 2019 | 7.5 | 25 | NO | NO |
CVE-2020-6238CRITICAL SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects co | Apr 14, 2020 | 9.3 | 23 | NO | NO |
CVE-2023-42481HIGH In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality t | Dec 12, 2023 | 8.1 | 21 | NO | NO |
CVE-2023-37486HIGH Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access information which would otherwise be rest | Aug 8, 2023 | 7.5 | 21 | NO | NO |
CVE-2021-33666MEDIUM When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or | Jun 9, 2021 | 6.1 | 20 | NO | NO |
CVE-2020-26809MEDIUM SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Sec | Nov 10, 2020 | 5.3 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
1 CVE
5.6% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Commerce Cloud
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| hy_com_1808 | 1 | 9.1 | 0.5% | 0 | 0 |
| com_cloud_2211 | 1 | 9.1 | 0.5% | 0 | 0 |
| 8.1 | 1 | 8.1 | 0.5% | 0 | 0 |
| 6.7 | 6 | 7.8 | 2.3% | 1 | 0 |
| 6.6 | 6 | 7.8 | 2.3% | 1 | 0 |
| 6.5 | 3 | 8.7 | 3.7% | 1 | 0 |
| 6.4 | 3 | 8.7 | 3.7% | 1 | 0 |
| 6.3 | 1 | 7.5 | 2.6% | 0 | 0 |
| 2211 | 4 | 7.1 | 0.4% | 0 | 0 |
| 2205 | 3 | 6.8 | 0.3% | 0 | 0 |
| 2105 | 1 | 9.1 | 0.5% | 0 | 0 |
| 2011 | 2 | 7.3 | 0.6% | 0 | 0 |
| 2005 | 5 | 6.0 | 0.8% | 0 | 0 |
| 1905 | 10 | 6.9 | 1.6% | 1 | 0 |
| 1811 | 12 | 6.8 | 1.6% | 1 | 0 |
| 1808 | 10 | 6.8 | 1.8% | 1 | 0 |
| 100 | 1 | 6.1 | 0.5% | 0 | 0 |