CVE-2024-41733: SAP Commerce

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

In SAP Commerce, valid user accounts can be identified during the customer registration and login processes. This allows a potential attacker to learn if a given e-mail is used for an account, but does not grant access to any customer data beyond this knowledge. The attacker must already know the e-mail that they wish to test for. The impact on confidentiality therefore is low and no impact to integrity or availability

Affected products

  • SAP Commerce: version com_cloud_2211 only; version hy_com_2205 only

Published 2024-08-13. Last modified 2026-06-17.