Advisory
A note with CVSS 8.1 for component CEC-SCC-PLA-PL was released by SAP on 14.07.2026. The correction/advisory 3763800 was described with "3763800 - [Multiple CVEs] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud" and affects the system type SAP Commerce Cloud.
A workaround exists, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is missing authentication checkweak security functionmissing authorization check within SAP Commerce Cloud.
Risk specification
SAP Commerce Cloud allows an unauthenticated attacker to bypass authentication and authorization controls or send specially crafted HTTP/2 request headers, potentially resulting in unauthorized access to protected resources and disruption of application processing.
Solution
SAP Commerce Cloud has resolved multiple security vulnerabilities in the embedded Apache Tomcat component related to Digest authentication handling, HTTP/2 request header validation, and authorization enforcement for overlapping security constraints. Although an alternative solution exists, it is advisable to apply the correction! This is the workaround, which was suggested by the SAP security experts: "Disable Digest authentication in custom web applications and HTTP/2 on affected Tomcat connectors (or terminate HTTP/2 at a reverse proxy), and consolidate overlapping security-constraint entries in custom web.xml files. Refer to SAP Note 3768608 for more information.".
