CVE-2025-26654

MEDIUM

SAP Commerce Cloud - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request before the redirect may be impacted if the client is configured to use HTTP and sends confidential data on the first request before the redirect.

Scores

CVSS v3 6.8
EPSS 0.0005
EPSS Percentile 16.0%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-319
Status published
Products (1)
SAP_SE/SAP Commerce Cloud (Public Cloud) COM_CLOUD 2211
Published Apr 08, 2025
Tracked Since Feb 18, 2026