Skip to main content

Vendor/product archive

sap / hybris CVEs

Beta · best-effort

8 CVEs tagged to sap / hybris0 Critical, 2 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2019-0238

Published Jan 8, 2019

SAP Commerce (previously known as SAP Hybris Commerce), before version 6.7, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerabil…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-2505

Published Dec 11, 2018

SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are based on the product. Fixed in ve…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-2463

Published Sep 11, 2018

The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML par…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2014-8871

Published Aug 28, 2017

Directory traversal vulnerability in hybris Commerce software suite 5.0.3.3 and earlier, 5.0.0.3 and earlier, 5.0.4.4 and earlier, 5.1.0.1 and earlier, 5.1.1.2 and earlier, 5.2.0.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6859

Published Dec 31, 2016

Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to obtain sensitive information by triggering an error and then reading a Java stack trace.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6858

Published Dec 31, 2016

Cross-site scripting (XSS) vulnerability in the Create Employee feature in Hybris Management Console (HMC) in SAP Hybris before 5.0.4.11, 5.1.0.x before 5.1.0.11, 5.1.1.x before 5…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6857

Published Dec 31, 2016

Cross-site scripting (XSS) vulnerability in the Create Catalogue feature in Hybris Management Console (HMC) in SAP Hybris before 5.2.0.13, 5.3.x before 5.3.0.11, 5.4.x before 5.4.…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6856

Published Dec 31, 2016

Cross-site scripting (XSS) vulnerability in the Inbox Search feature in Hybris Management Console (HMC) in SAP Hybris before 6.0 allows remote attackers to inject arbitrary web sc…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1