Critical severity9.3NVD Advisory· Published Apr 14, 2020· Updated Jun 17, 2026
CVE-2020-6238
CVE-2020-6238
Description
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.
Affected products
7cpe:2.3:a:sap:commerce_cloud:1808:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:sap:commerce_cloud:1808:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:1811:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:1905:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:6.6:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:6.7:*:*:*:*:*:*:*
- SAP SE/SAP Commercev5Range: < 6.6
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdBroken LinkVendor Advisory
News mentions
0No linked articles in our index yet.