Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3562415
was released on
11.03.2025 and deals with
"[CVE-2024-38819] Multiple vulnerabilities in Spring Framework within SAP Commerce Cloud and SAP Datahub" within SAP Commerce Cloud SAP DataHub.
We advice you to follow the instructions, to resolve
directory traversal (read)
with a
low potential for exploitation
in component CEC-SCC-PLA-PL.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
This note concerns two CVEs in Spring Framework which is a dependency of SAP Commerce Cloud and SAP Datahub: - SAP Commerce Cloud and SAP Datahub allow an attacker to exploit a path traversal vulnerability in the Spring Framework (CVE-2024-38819), resulting in unauthorized access to files on the server. - SAP Commerce Cloud and SAP Datahub allow an attacker to exploit a field manipulation vulnerability in the Spring Framework (CVE-2024-38820), resulting in manipulation of protected fields.Solution
The vulnerable Spring Framework versions have been updated to version 5.3 that does not contain the path traversal and field manipulation vulnerabilities.