Advisory
A note with CVSS 4.8 for component CEC-SCC-PLA-PL was released by SAP on 12.05.2026. The correction/advisory 3716450 was described with "3716450 - [CVE-2025-68161] Potential Improper Certificate Validation in SAP Commerce Cloud (Apache Log4j)" and affects the system type SAP Commerce Cloud.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is weak security function / cryptographic algorithm within SAP Commerce Cloud.
Risk specification
SAP Commerce Cloud uses an outdated Apache Log4j component with missing TLS hostname verification in the Socket Appender, allowing an unauthenticated network attacker to perform a man-in-the-middle attack on log connections, resulting in unauthorized access to or modification of log data in transit.
Solution
The Apache Log4j dependency has been upgraded to a version not affected by the vulnerability, eliminating the risk of man-in-the-middle attacks on log connections.
