CVE-2020-6363
- EPSS 0.21%
- Veröffentlicht 15.10.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:34
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change thei...
CVE-2020-6272
- EPSS 0.16%
- Veröffentlicht 15.10.2020 02:15:12
- Zuletzt bearbeitet 21.11.2024 05:35:25
SAP Commerce Cloud versions - 1808, 1811, 1905, 2005, does not sufficiently encode user inputs, which allows an authenticated and authorized content manager to inject malicious script into several web CMS components. These can be saved and later trig...
CVE-2020-6238
- EPSS 0.41%
- Veröffentlicht 14.04.2020 19:15:18
- Zuletzt bearbeitet 21.11.2024 05:35:21
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.
CVE-2020-6232
- EPSS 0.25%
- Veröffentlicht 14.04.2020 19:15:18
- Zuletzt bearbeitet 21.11.2024 05:35:20
SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.
CVE-2020-6201
- EPSS 0.37%
- Veröffentlicht 10.03.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:17
The SAP Commerce (Testweb Extension), versions- 6.6, 6.7, 1808, 1811, 1905, does not sufficiently encode user-controlled inputs, due to which certain GET URL parameters are reflected in the HTTP responses without escaping/sanitization, leading to Ref...
CVE-2020-6200
- EPSS 0.4%
- Veröffentlicht 10.03.2020 21:15:14
- Zuletzt bearbeitet 21.11.2024 05:35:17
The SAP Commerce (SmartEdit Extension), versions- 6.6, 6.7, 1808, 1811, is vulnerable to client-side angularjs template injection, a variant of Cross-Site-Scripting (XSS) that exploits the templating facilities of the angular framework.
CVE-2019-0344
- EPSS 50.7%
- Veröffentlicht 14.08.2019 14:15:16
- Zuletzt bearbeitet 27.01.2025 21:44:13
Due to unsafe deserialization used in SAP Commerce Cloud (virtualjdbc extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, it is possible to execute arbitrary code on a target machine with 'Hybris' user rights, resulting in Code Injection.
CVE-2019-0343
- EPSS 0.61%
- Veröffentlicht 14.08.2019 14:15:16
- Zuletzt bearbeitet 21.11.2024 04:16:42
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby co...
CVE-2019-0322
- EPSS 0.64%
- Veröffentlicht 10.07.2019 19:15:10
- Zuletzt bearbeitet 21.11.2024 04:16:40
SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.