CVE-2020-6238 is a critical missing XML validation vulnerability in SAP Commerce versions 6.6, 6.7, 1808, 1811, and 1905, specifically within the Rest API from Servlet xyformsweb. This flaw, with a CVSS score of 9.3, allows an unauthenticated attacker to remotely impact the confidentiality and partially the availability of affected systems with low attack complexity. While no public exploit code or active exploitation has been observed, the vulnerability has garnered limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.6CPE matchmatch criteria | cpe:2.3:a:sap:commerce_cloud:6.6:*:*:*:*:*:*:* | ||
6.7CPE matchmatch criteria | cpe:2.3:a:sap:commerce_cloud:6.7:*:*:*:*:*:*:* | ||
1808CPE matchmatch criteria | cpe:2.3:a:sap:commerce_cloud:1808:*:*:*:*:*:*:* | ||
1811CPE matchmatch criteria | cpe:2.3:a:sap:commerce_cloud:1811:*:*:*:*:*:*:* | ||
1905CPE matchmatch criteria | cpe:2.3:a:sap:commerce_cloud:1905:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.