CVE-2020-6302 Information
Feb 14, 2021
cve
Description
SAP Commerce versions 6.7 1808 1811 1905 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts leading to Session Fixation and complete compromise of the confidentiality integrity and availability of the application.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://launchpad.support.sap.com//notes/2934451 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=557449700
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: