cve/2024/CVE-2024-33003.md
2025-09-29 21:09:30 +02:00

1.7 KiB

CVE-2024-33003

Description

Some OCC API endpoints in SAP Commerce Cloudallows Personally Identifiable Information (PII) data, such as passwords, emailaddresses, mobile numbers, coupon codes, and voucher codes, to be included inthe request URL as query or path parameters. On successful exploitation, thiscould lead to a High impact on confidentiality and integrity of theapplication.

POC

Reference

No PoCs from references.

Github