The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with user?initiated interaction, may allow modifications to occur without validation. Such changes could affect system behaviour during startup, resulting in a high impact on the application's confidentiality and integrity, with a low impact on availability.
History

Tue, 10 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Sap Se
Sap Se sap Customer Checkout 2.0
Vendors & Products Sap Se
Sap Se sap Customer Checkout 2.0

Tue, 10 Mar 2026 00:45:00 +0000

Type Values Removed Values Added
Description The SAP Customer Checkout application exhibits certain design characteristics that involve locally storing operational data using reversible protection mechanisms. Access to this data, combined with user?initiated interaction, may allow modifications to occur without validation. Such changes could affect system behaviour during startup, resulting in a high impact on the application's confidentiality and integrity, with a low impact on availability.
Title Insecure Storage Protection vulnerability in SAP Customer Checkout 2.0
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2026-03-10T00:17:30.184Z

Updated: 2026-03-10T16:53:26.731Z

Reserved: 2026-01-21T22:15:25.361Z

Link: CVE-2026-24311

cve-icon Vulnrichment

Updated: 2026-03-10T15:39:54.737Z

cve-icon NVD

Status : Received

Published: 2026-03-10T17:35:55.360

Modified: 2026-03-10T17:35:55.360

Link: CVE-2026-24311

cve-icon Redhat

No data.