SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the user can iteratively enter one character at a time to search and determine the masked attribute value thereby leading to information disclosure.
2021-05-11T15:15:08.473
2024-11-21T05:58:18.733
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | sap | commerce | 1808 | Yes |
Application | sap | commerce | 1811 | Yes |
Application | sap | commerce | 1905 | Yes |
Application | sap | commerce | 2005 | Yes |
Application | sap | commerce | 2011 | Yes |