CVE-2020-26811: SSRF
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads to Server Side Request Forgery attack which could lead to retrieval of limited pieces of information about the service with no impact on integrity or availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26811?
CVE-2020-26811 has a high severity rating due to its potential for server-side request forgery.
How do I fix CVE-2020-26811?
To fix CVE-2020-26811, upgrade to a patched version of SAP Commerce Cloud that addresses this vulnerability.
What versions of SAP Commerce Cloud are affected by CVE-2020-26811?
CVE-2020-26811 affects SAP Commerce Cloud versions 1808, 1811, 1905, and 2005.
What impact does CVE-2020-26811 have on my system?
CVE-2020-26811 allows unauthenticated attackers to submit malicious requests, potentially compromising your system.
Is there a known exploit for CVE-2020-26811?
Yes, CVE-2020-26811 is associated with known exploits that leverage server-side request forgery techniques.