Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-62q9-rf2f-c4rj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.

SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.

EPSS

Процентиль: 49%
0.00262
Низкий

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 5.3
nvd
около 5 лет назад

SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.

EPSS

Процентиль: 49%
0.00262
Низкий

Дефекты

CWE-276