PT-2020-16497 · Sap · Sap Commerce Cloud

Published

2020-11-10

·

Updated

2020-11-23

·

CVE-2020-26810

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions SAP Commerce Cloud (Accelerator Payment Mock) versions 1808, 1811, 1905, 2005
Description The issue allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL, which will be processed without further interaction. This crafted request can render the SAP Commerce service itself unavailable, leading to Denial of Service with no impact on confidentiality or integrity.
Recommendations For versions 1808, 1811, 1905, 2005, consider restricting access to the SAP Commerce module URL to minimize the risk of exploitation. As a temporary workaround, consider disabling the vulnerable SAP Commerce module until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-26810

Affected Products

Sap Commerce Cloud