SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed. This could potentially bypass configured access restrictions, resulting in a low impact on confidentiality, with no impact on the integrity or availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Oct 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 14 Oct 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP Commerce Cloud contains a path traversal vulnerability that may allow users to access web applications such as the Administration Console from addresses where the Administration Console is not explicitly deployed. This could potentially bypass configured access restrictions, resulting in a low impact on confidentiality, with no impact on the integrity or availability of the application. | |
Title | Directory Traversal vulnerability in SAP Commerce Cloud | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-10-14T00:17:48.076Z
Updated: 2025-10-14T15:23:19.287Z
Reserved: 2025-04-16T13:25:25.736Z
Link: CVE-2025-42906

Updated: 2025-10-14T15:23:15.451Z

Status : Awaiting Analysis
Published: 2025-10-14T01:15:32.317
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-42906

No data.