Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.
History

Tue, 11 Mar 2025 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 01:00:00 +0000

Type Values Removed Values Added
Description Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.
Title Cross-Site Scripting (XSS) vulnerability in SAP Commerce (Swagger UI)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-03-11T02:04:11.442Z

Reserved: 2025-02-25T09:29:51.244Z

Link: CVE-2025-27434

cve-icon Vulnrichment

Updated: 2025-03-11T02:04:06.158Z

cve-icon NVD

Status : Received

Published: 2025-03-11T01:15:36.760

Modified: 2025-03-11T01:15:36.760

Link: CVE-2025-27434

cve-icon Redhat

No data.