CVE-2020-26811
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction,…
Does this matter?
Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.
Description
SAP Commerce Cloud (Accelerator Payment Mock), versions - 1808, 1811, 1905, 2005, allows an unauthenticated attacker to submit a crafted request over a network to a particular SAP Commerce module URL which will be processed without further interaction, the crafted request leads to Server Side Request Forgery attack which could lead to retrieval of limited pieces of information about the service with no impact on integrity or availability.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-918
- Affected
- sap/commerce cloud \(accelerator payment mock\)
- Source
- cna@sap.com
References
- http://packetstormsecurity.com/files/163143/SAP-Hybris-eCommerce-Server-Side-Request-Forgery.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Jun/26Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2975170Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571Vendor Advisory
- http://packetstormsecurity.com/files/163143/SAP-Hybris-eCommerce-Server-Side-Request-Forgery.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2021/Jun/26Mailing List, Third Party Advisory
- https://launchpad.support.sap.com/#/notes/2975170Permissions Required, Vendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.