CVE Database
/

CVE-2020-6363

Back to search

CVE-2020-6363

Published: Oct 15, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change their own passphrase, but this does not invalidate active sessions that the user may have with SAP Commerce Cloud web applications, which gives an attacker the opportunity to reuse old session credentials, resulting in Insufficient Session Expiration.

VendorProductVersions

SAP SE

SAP Commerce Cloud

affected
< 1808
affected
< 1811
affected
< 1905
affected
< 2005

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now