Session Management Vulnerability in SAP Commerce Software
CVE-2020-6302
6.4MEDIUM
Summary
SAP Commerce versions 6.7, 1808, 1811, 1905, and 2005 expose the jSession ID in the backoffice URL during initial loading. This exposure allows attackers to capture this ID through shoulder surfing or man-in-the-middle attacks. Once the session ID is obtained, attackers can exploit this vulnerability to initiate session fixation attacks, compromising admin user accounts and potentially affecting the overall confidentiality, integrity, and availability of the application. Organizations using these affected versions should take immediate steps to secure their systems against this vulnerability.
Affected Version(s)
SAP Commerce < 6.7 < 6.7
SAP Commerce < 1808 < 1808
SAP Commerce < 1811 < 1811
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved