CVE-2020-6363
- EPSS 0.21%
- Published 15.10.2020 02:15:12
- Last modified 21.11.2024 05:35:34
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change thei...
CVE-2020-6272
- EPSS 0.16%
- Published 15.10.2020 02:15:12
- Last modified 21.11.2024 05:35:25
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later trig...
CVE-2020-6238
- EPSS 0.41%
- Published 14.04.2020 19:15:18
- Last modified 21.11.2024 05:35:21
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.
CVE-2020-6232
- EPSS 0.25%
- Published 14.04.2020 19:15:18
- Last modified 21.11.2024 05:35:20
SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.
CVE-2020-6201
- EPSS 0.37%
- Published 10.03.2020 21:15:14
- Last modified 21.11.2024 05:35:17
The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without escaping/sanitization, leading to Ref...
CVE-2020-6200
- EPSS 0.4%
- Published 10.03.2020 21:15:14
- Last modified 21.11.2024 05:35:17
The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.
CVE-2019-0344
- EPSS 50.7%
- Published 14.08.2019 14:15:16
- Last modified 27.01.2025 21:44:13
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
CVE-2019-0343
- EPSS 0.61%
- Published 14.08.2019 14:15:16
- Last modified 21.11.2024 04:16:42
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby co...
CVE-2019-0322
- EPSS 0.64%
- Published 10.07.2019 19:15:10
- Last modified 21.11.2024 04:16:40
SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.