Loading
SAP Commerce Cloud may accept an empty passphrase for user ID and passphrase authentication, allowing users to log into the system without a passphrase.
Use CWE-258, Sap vendor hub and Commerce Cloud product page to widen CVE-2023-39439 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-6238, CVE-2023-42481 and CVE-2024-33003 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.