Loading HuntDB...

GHSA-7m3q-23p4-mw4v

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Some OCC API endpoints in SAP Commerce Cloud
allows Personally Identifiable Information (PII) data, such as passwords, email
addresses, mobile numbers, coupon codes, and voucher codes, to be included in
the request URL as query or path parameters. On successful exploitation, this
could lead to a High impact on confidentiality and integrity of the
application.

Related CVEs

Key Information

GHSA ID
GHSA-7m3q-23p4-mw4v
Published
August 13, 2024 6:30 AM
Last Modified
August 13, 2024 6:30 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.