SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.
2021-01-12T15:15:14.360
2024-11-21T05:48:23.317
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | sap | commerce_cloud | 1808 | Yes |
| Application | sap | commerce_cloud | 1811 | Yes |
| Application | sap | commerce_cloud | 1905 | Yes |
| Application | sap | commerce_cloud | 2005 | Yes |
| Application | sap | commerce_cloud | 2011 | Yes |