CVE-2020-6272
SAP Commerce Cloud vulnerability analysis and mitigation

Overview

CVE-2020-6272 is a Cross-Site Scripting (XSS) vulnerability affecting SAP Commerce Cloud versions 1808, 1811, 1905, and 2005. The vulnerability was discovered and reported on January 8, 2020. The issue occurs when the system does not sufficiently encode user inputs, allowing an authenticated and authorized content manager to inject malicious script into several web CMS components (CVE MITRE, CERT-FR).

Technical details

The vulnerability exists due to insufficient encoding of user inputs in SAP Commerce Cloud's web CMS components. When exploited, the malicious scripts can be saved and later triggered when an affected web page is visited. This creates a stored XSS condition that can be activated by visiting the compromised page (CVE MITRE).

Impact

The vulnerability allows authenticated and authorized content managers to inject malicious scripts into web CMS components. These scripts can be executed when other users visit the affected pages, potentially leading to unauthorized access to user data, session hijacking, or other malicious activities typical of XSS attacks (CERT-FR).

Exploitability

The vulnerability requires authentication and content manager authorization to exploit, which limits its potential impact. The attacker must have valid credentials and appropriate permissions within the SAP Commerce Cloud system to inject the malicious scripts (CVE MITRE).

Mitigation and workarounds

SAP has released security patches to address this vulnerability. Organizations using affected versions of SAP Commerce Cloud (1808, 1811, 1905, 2005) should apply the available security updates. The fix is documented in SAP Security Note 2917381 (SAP Note).

Additional resources


SourceThis report was generated using AI

Related SAP Commerce Cloud vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58231CRITICAL10
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoAug 11, 2026
CVE-2026-34263CRITICAL9.6
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoMay 12, 2026
CVE-2024-33003CRITICAL9.1
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoAug 13, 2024
CVE-2026-23684MEDIUM5.9
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoFeb 10, 2026
CVE-2026-24321MEDIUM5.3
  • SAP Commerce Cloud logoSAP Commerce Cloud
  • cpe:2.3:a:sap:commerce_cloud
NoNoFeb 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management