Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3757815
was released on
11.08.2026 and deals with
"3757815 - [CVE-2026-5598] Potential Information Disclosure vulnerability in SAP Commerce Cloud (Bouncy Castle Java library)" within SAP Commerce Cloud.
We advice you to follow the instructions, to resolve
weak security function / cryptographic algorithm
with a
medium potential for exploitation
in component CEC-SCC-PLA-PL.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
SAP Commerce Cloud uses a vulnerable version of the Bouncy Castle Java library that allows an unauthenticated attacker to observe timing differences during cryptographic operations and recover sensitive key material, resulting in unauthorized access to protected data.
Solution
SAP Commerce Cloud has been updated to a version of Bouncy Castle that is not affected by the referenced vulnerability. The fix is included in Update Releases 2211.52 and 2211-jdk21.11.
