Commerce Cloud

Vendor:

First CVE: Jul 10, 2019 · Active for 7 years

18
Total CVEs
More Total CVEs than 93% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
5.6%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Commerce Cloud over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 10, 2019
7 years ago
Most Recent CVE
Feb 10, 2026
164 days ago

CVE Severity & Scoring

Commerce Cloud18 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None12 (66.7%)
Unknown0 (0.0%)
Required6 (33.3%)
Privileges Required
Low6 (33.3%)
High0 (0.0%)
None12 (66.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a targe
Aug 14, 20199.873YESNO
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.
Aug 8, 20239.830NONO
Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher co
Aug 13, 20249.126NONO
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by th
Aug 14, 20198.826NONO
SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing
Jul 10, 20197.525NONO
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects co
Apr 14, 20209.323NONO
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality t
Dec 12, 20238.121NONO
Under certain conditions SAP Commerce (OCC API) - versions HY_COM 2105, HY_COM 2205, COM_CLOUD 2211, endpoints allow an attacker to access information which would otherwise be rest
Aug 8, 20237.521NONO
When SAP Commerce Cloud version 100, hosts a JavaScript storefront, it is vulnerable to MIME sniffing, which, in certain circumstances, could be used to facilitate an XSS attack or
Jun 9, 20216.120NONO
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Sec
Nov 10, 20205.320NONO

Exploit Exposure

Signals from CVEs in this product scope (18 CVEs).

CISA KEV
1 CVE
5.6% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (18 CVEs).

Media Mentions

Signals from CVEs in this product scope (18 CVEs).

Top CNAs Publishing CVEs For Commerce Cloud

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
hy_com_180819.10.5%00
com_cloud_221119.10.5%00
8.118.10.5%00
6.767.82.3%10
6.667.82.3%10
6.538.73.7%10
6.438.73.7%10
6.317.52.6%00
221147.10.4%00
220536.80.3%00
210519.10.5%00
201127.30.6%00
200556.00.8%00
1905106.91.6%10
1811126.81.6%10
1808106.81.8%10
10016.10.5%00