CVE-2024-33003: SAP Commerce Cloud

Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.

Affected products

  • SAP Commerce Cloud: version 1811 only; version 1905 only; version 2005 only; version 2011 only; version 2105 only; version 2205 only; …

Published 2024-08-13. Last modified 2026-06-17.