CVE-2020-6363: Medium severity sap commerce vulnerability
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change their own passphrase, but this does not invalidate active sessions that the user may have with SAP Commerce Cloud web applications, which gives an attacker the opportunity to reuse old session credentials, resulting in Insufficient Session Expiration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-6363?
CVE-2020-6363 is rated as a high severity vulnerability.
How do I fix CVE-2020-6363?
To fix CVE-2020-6363, upgrade to a patched version of SAP Commerce Cloud that addresses this vulnerability.
What versions of SAP Commerce Cloud are affected by CVE-2020-6363?
CVE-2020-6363 affects SAP Commerce Cloud versions 1808, 1811, 1905, and 2005.
What is the impact of CVE-2020-6363 on user sessions?
CVE-2020-6363 allows user sessions to remain valid even after a user changes their passphrase.
Can CVE-2020-6363 lead to unauthorized access?
Yes, CVE-2020-6363 can potentially lead to unauthorized access if proper session invalidation is not implemented.