SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the /medias endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Commerce_cloud | Sap | 1808 (including) | 1808 (including) |
Commerce_cloud | Sap | 1811 (including) | 1811 (including) |
Commerce_cloud | Sap | 1905 (including) | 1905 (including) |
Commerce_cloud | Sap | 2005 (including) | 2005 (including) |