SAP Knowledge Base Article - Preview

3525343 - Potential security issue due to missing rate limiting allowing rapid repeated requests

Symptom

The issue occurs on non-transactional pages due to missing rate limiting on the email parameter (and similar fields across these pages), allowing rapid repeated requests that can flood the admin inbox, strain API resources such as CPU, storage, and memory, and prevent the expected 429 error from being triggered.


Read more...

Environment

  • SAP Commerce Cloud
  • SAP Commerce Cloud, Composable Storefront

Product

SAP Commerce Cloud all versions ; SAP Commerce Cloud, composable storefront all versions

Keywords

Transaction, pages, missing, rate, limiting, email, parameter, fields, CPU, API, 429, memory, storage, vulnerabilities, lack, WAF, environment, endpoint, blocking, traffic, ccv2, hybris , KBA , CEC-SPA , SAP Commerce Cloud Spartacus , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.