First published: Tue Nov 10 2020(Updated: )
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Commerce Cloud | =1808 | |
SAP Commerce Cloud | =1811 | |
SAP Commerce Cloud | =1905 | |
SAP Commerce Cloud | =2005 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-26809.
The severity of CVE-2020-26809 is medium with a CVSS score of 5.3.
SAP Commerce Cloud versions 1808, 1811, 1905, and 2005 are affected by CVE-2020-26809.
CVE-2020-26809 allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint, gaining access to Secure Media folders.
The impact of CVE-2020-26809 is the disclosure of sensitive information and potential unauthorized access to sensitive files.