CVE-2020-26810: High severity sap commerce cloud vulnerability
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request can render the SAP Commerce service itself unavailable leading to Denial of Service with no impact on confidentiality or integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26810?
CVE-2020-26810 is considered a critical vulnerability due to its ability to allow unauthenticated access to sensitive functionalities.
How do I fix CVE-2020-26810?
To fix CVE-2020-26810, it is recommended to apply the latest security patches provided by SAP for affected versions.
Which versions of SAP Commerce Cloud are affected by CVE-2020-26810?
CVE-2020-26810 affects SAP Commerce Cloud versions 1808, 1811, 1905, and 2005.
What type of attack does CVE-2020-26810 enable?
CVE-2020-26810 enables an unauthenticated attacker to submit crafted requests that can be processed by the SAP Commerce module.
Is authentication required to exploit CVE-2020-26810?
No, CVE-2020-26810 can be exploited without authentication, making it particularly dangerous.