PT-2020-19060 · Sap · Sap Commerce

Published

2020-06-09

·

Updated

2020-06-15

·

CVE-2020-6265

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Commerce versions 6.7, 1808, 1811, 1905 SAP Commerce (Data Hub) versions 6.7, 1808, 1811, 1905
Description The issue allows an attacker to bypass the authentication and/or authorization configured by the system administrator due to the use of Hardcoded Credentials.
Recommendations For SAP Commerce versions 6.7, 1808, 1811, 1905, remove or update the hardcoded credentials to prevent unauthorized access. For SAP Commerce (Data Hub) versions 6.7, 1808, 1811, 1905, remove or update the hardcoded credentials to prevent unauthorized access.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6265

Affected Products

Sap Commerce