CVE Published: 10/11/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: sap |
Vendor: SAP SE |
Product: SAP Commerce Cloud Status : PUBLISHED
CVE-2020-26809 Description
SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the \'/medias\' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.