CyberRota Analysis
AI-GeneratedSAP Commerce Cloud is vulnerable due to the retention of a sample OAuth2 client with publicly documented credentials, which can be exploited by unauthenticated attackers. This allows attackers to obtain valid access tokens, enabling them to read and modify sensitive data, thereby severely compromising confidentiality and integrity. Organizations using SAP Commerce Cloud should prioritize remediation to mitigate this critical risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability.