Description
The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side implementation of OCC.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-14318 | The Omni Commerce Connect API (OCC) of SAP Hybris Commerce, versions 6.*, is vulnerable to server-side request forgery (SSRF) attacks. This is due to a misconfiguration of XML parser that is used in the server-side implementation of OCC. |
References
History
No history.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2024-08-05T04:21:34.044Z
Reserved: 2017-12-15T00:00:00.000Z
Link: CVE-2018-2463
No data.
Status : Modified
Published: 2018-09-11T15:29:01.890
Modified: 2024-11-21T04:03:51.583
Link: CVE-2018-2463
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD