CVE-2024-39597
Severity CVSS v4.0:
Pending analysis
Type:
CWE-285
Improper Authorization
Publication date:
09/07/2024
Last modified:
09/07/2024
Description
In SAP Commerce, a user can misuse the forgotten<br />
password functionality to gain access to a Composable Storefront B2B site for<br />
which early login and registration is activated, without requiring the merchant<br />
to approve the account beforehand. If the site is not configured as isolated<br />
site, this can also grant access to other non-isolated early login sites, even<br />
if registration is not enabled for those other sites.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH



