Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3692405
was released on
10.02.2026 and deals with
"[CVE-2025-12383] Race Condition in SAP Commerce Cloud" within SAP Commerce Cloud.
We advice you to follow the instructions, to resolve
missing security configuration
with a
high potential for exploitation
in component CEC-SCC-PLA-PL.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
SAP Commerce Cloud allows an authenticated attacker to bypass SSL trust validation during outbound connections due to a race condition in SSL trust handling, potentially resulting in unauthorized manipulation of trusted communication channels.
Solution
SAP Commerce Cloud now uses updated Jersey libraries that properly synchronize SSL trust handling during concurrent requests, preventing attackers from bypassing SSL trust validation on outbound connections.
