{"cve":{"cve_id":"CVE-2025-27435","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00192,"epss_percentile":0.08962,"epss_as_of":"2026-06-23","description":"Under specific conditions and prerequisites, an unauthenticated attacker could access customer coupon codes exposed in the URL parameters of the Coupon Campaign URL in SAP Commerce. This could allow the attacker to use the disclosed coupon code, hence posing a low impact on confidentiality and integrity of the application.","published_at":"2025-04-08T07:13:49.402000Z","last_modified_at":null,"cvss_v3_score":4.2,"cvss_v3_vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N","cvss_v3_severity":"MEDIUM","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":["CWE-862"],"nvd_references":["https://me.sap.com/notes/3539465","https://url.sap/sapsecuritypatchday"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:26:08.366577Z"},"effective_severity":"MEDIUM","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"H","value_label":"High"},{"metric":"PR","name":"Privileges Required","value":"N","value_label":"None"},{"metric":"UI","name":"User Interaction","value":"R","value_label":"Required"},{"metric":"S","name":"Scope","value":"U","value_label":"Unchanged"},{"metric":"C","name":"Confidentiality","value":"L","value_label":"Low"},{"metric":"I","name":"Integrity","value":"L","value_label":"Low"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-commerce-cloud","product_name":"SAP Commerce Cloud","version_start":"HY_COM 2205","version_start_inclusive":true,"version_end":"HY_COM 2205","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-commerce-cloud:HY_COM 2205:HY_COM 2205"},{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-commerce-cloud","product_name":"SAP Commerce Cloud","version_start":"COM_CLOUD 2211","version_start_inclusive":true,"version_end":"COM_CLOUD 2211","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-commerce-cloud:COM_CLOUD 2211:COM_CLOUD 2211"}],"exploit_refs":[],"news":[],"references":[{"url":"https://me.sap.com/notes/3539465","source_type":"MISC","tags":[]},{"url":"https://url.sap/sapsecuritypatchday","source_type":"MISC","tags":["patch"]}],"timeline":[{"type":"published","at":"2025-04-08T07:13:49.402000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:44:10.186200Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:44:10.186200Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:44:10.186200Z","label":"CVSS score revised","source":"cvelistv5"}]}