In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005...
High severity
Unreviewed
Published
Dec 12, 2023
to the GitHub Advisory Database
•
Updated Sep 29, 2024
Description
Published by the National Vulnerability Database
Dec 12, 2023
Published to the GitHub Advisory Database
Dec 12, 2023
Last updated
Sep 29, 2024
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP Commerce Cloud - Composable Storefront is used as storefront, due to weak access controls in place. This leads to a considerable impact on confidentiality and integrity.
References