CVE-2020-6302: High severity sap commerce cloud vulnerability
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6302?
CVE-2020-6302 has a high severity rating due to its potential to allow unauthorized access to admin accounts.
How do I fix CVE-2020-6302?
To fix CVE-2020-6302, upgrade to a patched version of SAP Commerce that does not include the jSession ID in the backoffice URL.
Who is affected by CVE-2020-6302?
CVE-2020-6302 affects SAP Commerce versions 6.7, 1808, 1811, 1905, and 2005.
What types of attacks can exploit CVE-2020-6302?
CVE-2020-6302 can be exploited through shoulder surfing and man-in-the-middle attacks.
What can an attacker do with CVE-2020-6302?
An attacker can gain access to admin user accounts by retrieving the jSession ID through CVE-2020-6302.