First published: Tue Apr 14 2020(Updated: )
SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Commerce Cloud | =1811 | |
SAP Commerce Cloud | =1905 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-6232.
SAP Commerce versions 1811 and 1905 are affected by this vulnerability.
The severity rating for this vulnerability is medium with a score of 5.3.
This vulnerability affects the confidentiality of secure media.
To fix this vulnerability, apply the necessary authorization checks for anonymous users.