PT-2020-16497 · Sap · Sap Commerce Cloud
Published
2020-11-10
·
Updated
2020-11-23
·
CVE-2020-26810
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Commerce Cloud (Accelerator Payment Mock) versions 1808, 1811, 1905, 2005
Description
The issue allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL, which will be processed without further interaction. This crafted request can render the SAP Commerce service itself unavailable, leading to Denial of Service with no impact on confidentiality or integrity.
Recommendations
For versions 1808, 1811, 1905, 2005, consider restricting access to the SAP Commerce module URL to minimize the risk of exploitation.
As a temporary workaround, consider disabling the vulnerable SAP Commerce module until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Commerce Cloud