PT-2020-19034 · Sap · Sap Commerce

Published

2020-04-14

·

Updated

2022-10-06

·

CVE-2020-6238

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
Name of the Vulnerable Software and Affected Versions SAP Commerce versions 6.6, 6.7, 1808, 1811, 1905
Description The issue is related to the insecure processing of XML input in the Rest API from the Servlet xyformsweb, leading to Missing XML Validation. This affects the confidentiality and availability of SAP Commerce.
Recommendations For SAP Commerce versions 6.6, 6.7, 1808, 1811, 1905, update the software to a version that securely processes XML input in the Rest API. As a temporary workaround, consider restricting access to the vulnerable Servlet xyformsweb to minimize the risk of exploitation. Avoid using the vulnerable Rest API endpoint until the issue is resolved.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2020-6238

Affected Products

Sap Commerce