CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.6. See the original NVD description below for full technical details.
CVE
CVE-2018-2463
Severity
HIGH
CVSS
8.6
EPSS
1.64%
Original NVD Description
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side implementation of OCC.
Related CVEs
Other vulnerabilities affecting the same vendor(s)