5
CVSSv2

CVE-2020-26809

Published: 10/11/2020 Updated: 17/06/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an malicious user to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap commerce cloud 1808

sap commerce cloud 1811

sap commerce cloud 1905

sap commerce cloud 2005

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Onapsis Security Advisory 2021-0007: Exposure of Sensitive Information to an Unauthorized Actor <!--X-Subject-Header-E ...