VYPR
Critical severity9.8NVD Advisory· Published Jun 9, 2020· Updated Jun 17, 2026

CVE-2020-6265

CVE-2020-6265

Description

SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization that has been configured by the system administrator due to the use of Hardcoded Credentials.

Affected products

12
  • SAP/Commerce5 versions
    cpe:2.3:a:sap:commerce:1808:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:sap:commerce:1808:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:commerce:1811:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:commerce:1905:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:commerce:6.7:*:*:*:*:*:*:*
    • (no CPE)range: 6.7, 1808, 1811, 1905
  • cpe:2.3:a:sap:commerce_data_hub:1808:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:sap:commerce_data_hub:1808:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:commerce_data_hub:1811:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:commerce_data_hub:1905:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:commerce_data_hub:6.7:*:*:*:*:*:*:*
    • (no CPE)range: 6.7, 1808, 1811, 1905
  • SAP SE/SAP Commercev5
    Range: < 6.7
  • SAP SE/SAP Commerce (Data Hub)v5
    Range: < 6.7

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.