Session Management Vulnerability in SAP Commerce Software
CVE-2020-6302

6.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 September 2020

Summary

SAP Commerce versions 6.7, 1808, 1811, 1905, and 2005 expose the jSession ID in the backoffice URL during initial loading. This exposure allows attackers to capture this ID through shoulder surfing or man-in-the-middle attacks. Once the session ID is obtained, attackers can exploit this vulnerability to initiate session fixation attacks, compromising admin user accounts and potentially affecting the overall confidentiality, integrity, and availability of the application. Organizations using these affected versions should take immediate steps to secure their systems against this vulnerability.

Affected Version(s)

SAP Commerce < 6.7 < 6.7

SAP Commerce < 1808 < 1808

SAP Commerce < 1811 < 1811

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.