Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Filtered by product Commerce
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-40502 1 Sap 1 Commerce 2021-11-28 6.5 MEDIUM 8.8 HIGH
SAP Commerce - versions 2105.3, 2011.13, 2005.18, 1905.34, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. Authenticated attackers will be able to access and edit data from b2b units they do not belong to.
CVE-2020-6264 1 Sap 1 Commerce 2021-07-21 5.0 MEDIUM 7.5 HIGH
SAP Commerce, versions - 6.7, 1808, 1811, 1905, may allow an attacker to access information under certain conditions which would otherwise be restricted, leading to Information Disclosure.
CVE-2020-6302 1 Sap 1 Commerce 2020-09-10 7.5 HIGH 8.1 HIGH
SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.