Vulnerability Description
In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Commerce | com_cloud_2211 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3471450Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
FAQ
What is CVE-2024-41733?
CVE-2024-41733 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but doe...
How severe is CVE-2024-41733?
CVE-2024-41733 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41733?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Commerce.