Some OCC API endpoints in SAP Commerce Cloud allows Personally Identifiable Information (PII) data, such as passwords, email addresses, mobile numbers, coupon codes, and voucher codes, to be included in the request URL as query or path parameters. On successful exploitation, this could lead to a High impact on confidentiality and integrity of the application.
Use CWE-200, Sap vendor hub and Commerce Cloud product page to widen CVE-2024-33003 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-6238, CVE-2023-39439 and CVE-2023-42481 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.