CVE Published: 14/04/2020 |
CVE Updated: 04/08/2024 |
CVE Year: 2020 Source: sap |
Vendor: SAP SE |
Product: SAP Commerce Status : PUBLISHED
CVE-2020-6238 Description
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.