Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41204


An attacker can change the content of an SAP Commerce - versions 1905, 2005, 2105, 2011, 2205, login page through a manipulated URL. They can inject code that allows them to redirect submissions from the affected login form to their own server. This allows them to steal credentials and hijack accounts. A successful attack could compromise the Confidentiality, Integrity, and Availability of the system.


Published

2022-10-11T21:15:26.377

Last Modified

2025-05-20T16:15:22.673

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap commerce 1905 Yes
Application sap commerce 2005 Yes
Application sap commerce 2011 Yes
Application sap commerce 2105 Yes
Application sap commerce 2205 Yes

References