
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-6272 is a Cross-Site Scripting (XSS) vulnerability affecting SAP Commerce Cloud versions 1808, 1811, 1905, and 2005. The vulnerability was discovered and reported on January 8, 2020. The issue occurs when the system does not sufficiently encode user inputs, allowing an authenticated and authorized content manager to inject malicious script into several web CMS components (CVE MITRE, CERT-FR).
The vulnerability exists due to insufficient encoding of user inputs in SAP Commerce Cloud's web CMS components. When exploited, the malicious scripts can be saved and later triggered when an affected web page is visited. This creates a stored XSS condition that can be activated by visiting the compromised page (CVE MITRE).
The vulnerability allows authenticated and authorized content managers to inject malicious scripts into web CMS components. These scripts can be executed when other users visit the affected pages, potentially leading to unauthorized access to user data, session hijacking, or other malicious activities typical of XSS attacks (CERT-FR).
The vulnerability requires authentication and content manager authorization to exploit, which limits its potential impact. The attacker must have valid credentials and appropriate permissions within the SAP Commerce Cloud system to inject the malicious scripts (CVE MITRE).
SAP has released security patches to address this vulnerability. Organizations using affected versions of SAP Commerce Cloud (1808, 1811, 1905, 2005) should apply the available security updates. The fix is documented in SAP Security Note 2917381 (SAP Note).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."