CVE-2025-27434

HIGH

SAP Commerce (Swagger UI) COM_CLOUD 2211 - Unauthenticated Cross-Site Scripting

Title source: llm
STIX 2.1

Description

Due to insufficient input validation, SAP Commerce (Swagger UI) allows an unauthenticated attacker to inject the malicious code from remote sources, which can be leveraged by an attacker to execute a cross-site scripting (XSS) attack. This could lead to a high impact on the confidentiality, integrity, and availability of data in SAP Commerce.

References (2)

Core 2
Core References

Scores

CVSS v3 8.8
EPSS 0.0023
EPSS Percentile 45.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-79
Status published
Products (1)
SAP_SE/SAP Commerce (Swagger UI) COM_CLOUD 2211
Published Mar 11, 2025
Tracked Since Feb 18, 2026