Improper Authorization in SAP Commerce Cloud Data Hub Adapter Allows Unauthenticated RCE
SAP Commerce Cloud (Data Hub Adapter)
CVSS 10.0 — perfect score. Unauthenticated code execution via a default authentication client means any network-accessible Commerce Cloud Data Hub is a one-step compromise. If you run Commerce Cloud with Data Hub integration, this is your only priority this month. Rotate the default credentials and patch before end of day.
Vulnerability Detail
An improper authorization vulnerability in the SAP Commerce Cloud Data Hub Adapter allows an unauthenticated attacker to abuse a default authentication client. Combined with specially crafted input, this enables arbitrary code execution on the underlying server — compromising confidentiality, integrity, and availability of the Commerce Cloud platform and any connected systems. Rated CVSS 10.0 — the maximum score.
Workaround
Disable or reconfigure the default authentication client in the Data Hub Adapter configuration until the patch is applied. Restrict inbound access to Data Hub endpoints at the network perimeter.
Patch Action
Apply SAP Note 3771065 and redeploy the updated Commerce Cloud version. Verify the Data Hub Adapter authentication configuration post-patch.
Patch Info