First published: Tue Nov 10 2020(Updated: )
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request can render the SAP Commerce service itself unavailable leading to Denial of Service with no impact on confidentiality or integrity.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Commerce Cloud | =1808 | |
SAP Commerce Cloud | =1811 | |
SAP Commerce Cloud | =1905 | |
SAP Commerce Cloud | =2005 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-26810 is considered a critical vulnerability due to its ability to allow unauthenticated access to sensitive functionalities.
To fix CVE-2020-26810, it is recommended to apply the latest security patches provided by SAP for affected versions.
CVE-2020-26810 affects SAP Commerce Cloud versions 1808, 1811, 1905, and 2005.
CVE-2020-26810 enables an unauthenticated attacker to submit crafted requests that can be processed by the SAP Commerce module.
No, CVE-2020-26810 can be exploited without authentication, making it particularly dangerous.