CVE-2024-39597

Severity CVSS v4.0:
Pending analysis
Type:
CWE-285 Improper Authorization
Publication date:
09/07/2024
Last modified:
09/07/2024

Description

In SAP Commerce, a user can misuse the forgotten<br /> password functionality to gain access to a Composable Storefront B2B site for<br /> which early login and registration is activated, without requiring the merchant<br /> to approve the account beforehand. If the site is not configured as isolated<br /> site, this can also grant access to other non-isolated early login sites, even<br /> if registration is not enabled for those other sites.