SAP Knowledge Base Article - Preview

3794859 - Disable Scripting access to Users on HAC manually via Backoffice

Symptom

- A critical Remote Code Execution (RCE) security vulnerability was identified in the SAP Commerce Cloud Production environment through the Hybris Administration Console (HAC).
- An authenticated user with access to HAC can execute Groovy scripts on the SAP Commerce application server.
- The vulnerability allows unauthorized access to sensitive information, execution of arbitrary operating-system commands, modification or deletion of files, and potential service disruption.


Read more...

Environment

SAP Commerce Cloud

Product

SAP Commerce Cloud 2211

Keywords

Diable HAC access, HAC scripting access , KBA , CEC-SCC-PLA-PL , Platform , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.