CVE-2020-26809: Medium severity sap commerce vulnerability
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-26809.
What is the severity of CVE-2020-26809?
The severity of CVE-2020-26809 is medium with a CVSS score of 5.3.
Which versions of SAP Commerce Cloud are affected by CVE-2020-26809?
SAP Commerce Cloud versions 1808, 1811, 1905, and 2005 are affected by CVE-2020-26809.
How does CVE-2020-26809 allow an attacker to gain unauthorized access?
CVE-2020-26809 allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint, gaining access to Secure Media folders.
What is the impact of CVE-2020-26809?
The impact of CVE-2020-26809 is the disclosure of sensitive information and potential unauthorized access to sensitive files.