Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application.
Metrics
Affected Vendors & Products
References
History
Wed, 09 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Apr 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application. | |
Title | Information Disclosure Vulnerability in SAP Commerce Cloud | |
Weaknesses | CWE-862 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-04-08T13:28:27.656Z
Reserved: 2025-02-25T09:29:51.244Z
Link: CVE-2025-27435

Updated: 2025-04-08T13:28:21.331Z

Status : Awaiting Analysis
Published: 2025-04-08T08:15:16.550
Modified: 2025-04-08T18:13:53.347
Link: CVE-2025-27435

No data.