SAP Commerce Cloud may accept an empty passphrase for...
Critical severity
Unreviewed
Published
Aug 8, 2023
to the GitHub Advisory Database
•
Updated Sep 29, 2024
Description
Published by the National Vulnerability Database
Aug 8, 2023
Published to the GitHub Advisory Database
Aug 8, 2023
Last updated
Sep 29, 2024
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.
References