Advisory
A note with CVSS 9.3 for component CEC-COM-CPS was released by SAP on 14.04.2020. The correction/advisory 2904480 was described with "[CVE-2020-6238] Missing XML Validation vulnerability in SAP Commerce" and affects the system type SAP Commerce Cloud.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is external entity tunneling (xxe) within SAP Commerce Cloud.
Risk specification
SAP Commerce does not sufficiently validate an XML document which affects confidentiality and availability (partially) of SAP Commerce.Solution
SAP Commerce has been updated to correctly validate XML input
- 9.8 Potential XML External Entity Injection Vulnerability in SAP Environmental Compliance
- 9.6 [CVE-2020-26831] Missing XML Validation in SAP BusinessObjects Business Intelligence Platform (Crystal Report)
- 8.7 [CVE-2021-27635] Missing XML Validation in SAP NetWeaver AS for JAVA
- 8.6 [CVE-2024-24743] XXE vulnerability in SAP NetWeaver AS Java (Guided Procedures)
- 7.7 [CVE-2020-6285] Information Disclosure in SAP NetWeaver (XMLToolkit for Java)