Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3620264
was released on
09.09.2025 and deals with
"[CVE-2025-22228] Security Misconfiguration vulnerability in Spring security within SAP Commerce Cloud and SAP Datahub" within SAP Commerce Cloud SAP DataHub.
We advice you to follow the instructions, to resolve
weak security function / cryptographic algorithm
with a
medium potential for exploitation
in component CEC-SCC-PLA-PL.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
SAP Commerce Cloud and SAP Data Hub use a vulnerable Spring Security component that allows unauthenticated attackers to bypass authentication with specially crafted long passwords, leading to unauthorized system access.Solution
The application now uses an updated Spring Security version that removes the vulnerable password handling.