Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3590984
was released on
08.04.2025 and deals with
"[CVE-2024-56337] Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat within SAP Commerce Cloud" within SAP Commerce Cloud.
We advice you to follow the instructions, to resolve
toctou race condition
with a
high potential for exploitation
in component CEC-SCC-CDM-CKP-COR.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
Apache Tomcat, as used within SAP Commerce Cloud, is affected by a time-of-check to time-of-use (TOCTOU) vulnerability that allows an unauthenticated attacker to manipulate a resource's state between validation and usage. This can lead to a complete compromise of the system's confidentiality, integrity, and availability.Solution
This potential vulnerability has been mitigated by upgrading Apache Tomcat to a version that is not affected by the TOCTOU (Time-of-Check to Time-of-Use) race condition vulnerability.