E Commerce

Vendor:

First CVE: May 14, 2019 · Active for 7 years

2
Total CVEs
More Total CVEs than 49% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 28% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact E Commerce over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 14, 2019
7 years ago
Most Recent CVE
Jun 12, 2019
2,601 days ago

CVE Severity & Scoring

E Commerce2 CVEs
All CVEs352,713 CVEs
Medium
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required2 (100.0%)
Privileges Required
Low1 (50.0%)
High0 (0.0%)
None1 (50.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (2 CVEs).

2 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An authenticated attacker in SAP E-Commerce (Business-to-Consumer application), versions 7.3, 7.31, 7.32, 7.33, 7.54, can change the price of the product to zero and also checkout,
Jun 12, 20196.823NONO
SAP E-Commerce (Business-to-Consumer) application does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. Fixed in the following
May 14, 20196.120NONO

Exploit Exposure

Signals from CVEs in this product scope (2 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (2 CVEs).

Media Mentions

Signals from CVEs in this product scope (2 CVEs).

Top CNAs Publishing CVEs For E Commerce

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.5426.51.1%00
7.3326.51.1%00
7.3226.51.1%00
7.3126.51.1%00
7.3026.51.1%00