CVE-2020-6232

MEDIUM

SAP Commerce <1905 - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP Commerce, versions 1811, 1905, does not perform necessary authorization checks for an anonymous user, due to Missing Authorization Check. This affects confidentiality of secure media.

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2888556

Scores

CVSS v3 5.3
EPSS 0.0025
EPSS Percentile 48.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-862
Status published
Products (2)
sap/commerce_cloud 1811
sap/commerce_cloud 1905
Published Apr 14, 2020
Tracked Since Feb 18, 2026