CVE Published: 13/08/2024 |
CVE Updated: 13/08/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP Commerce Status : PUBLISHED
CVE-2024-41733 Description
In SAP Commerce, valid user accounts can be
identified during the customer registration and login processes. This allows a
potential attacker to learn if a given e-mail is used for an account, but does
not grant access to any customer data beyond this knowledge. The attacker must
already know the e-mail that they wish to test for. The impact on
confidentiality therefore is low and no impact to integrity or availability
Metrics
CVSS Version: 3.1 |
Base Score: 5.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N