Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 2918924
was released on
09.06.2020 and deals with
"[CVE-2020-6265] Use of Hard-coded Credentials in SAP Commerce and SAP Commerce Datahub" within SAP Cloud Commerce.
We advice you to follow the instructions, to resolve
weak security defaults
with a
hot news potential for exploitation
in component CEC-COM-CPS.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as part of maintenance.
Risk specification
SAP Commerce and SAP Commerce Datahub allow an attacker to authenticate to the system with default credentials allowing full system access.Solution
The Installer no longer sets dedault passwords for default users and asks for a new password explicitly for new installations