SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request before the redirect may be impacted if the client is configured to use HTTP and sends confidential data on the first request before the redirect.
History

Tue, 08 Apr 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 07:30:00 +0000

Type Values Removed Values Added
Description SAP Commerce Cloud (Public Cloud) does not allow to disable unencrypted HTTP (port 80) entirely, but instead allows a redirect from port 80 to 443 (HTTPS). As a result, Commerce normally communicates securely over HTTPS. However, the confidentiality and integrity of data sent on the first request before the redirect may be impacted if the client is configured to use HTTP and sends confidential data on the first request before the redirect.
Title Potential information disclosure vulnerability in SAP Commerce Cloud (Public Cloud)
Weaknesses CWE-319
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-04-08T07:13:04.452Z

Updated: 2025-04-09T04:00:45.108Z

Reserved: 2025-02-12T21:05:31.735Z

Link: CVE-2025-26654

cve-icon Vulnrichment

Updated: 2025-04-08T13:20:12.933Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T08:15:15.903

Modified: 2025-04-08T18:13:53.347

Link: CVE-2025-26654

cve-icon Redhat

No data.