Critical severity9.8NVD Advisory· Published Jun 9, 2020· Updated Jun 17, 2026
CVE-2020-6265
CVE-2020-6265
Description
SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization that has been configured by the system administrator due to the use of Hardcoded Credentials.
Affected products
12cpe:2.3:a:sap:commerce_data_hub:1808:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:sap:commerce_data_hub:1808:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_data_hub:1811:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_data_hub:1905:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_data_hub:6.7:*:*:*:*:*:*:*
- (no CPE)range: 6.7, 1808, 1811, 1905
- SAP SE/SAP Commercev5Range: < 6.7
- SAP SE/SAP Commerce (Data Hub)v5Range: < 6.7
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.