Vulnerabilities > CVE-2020-6363 - Insufficient Session Expiration vulnerability in SAP Commerce Cloud

047910
CVSS 4.6 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
LOW
Integrity impact
LOW
Availability impact
NONE
network
low complexity
sap
CWE-613

Summary

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, exposes several web applications that maintain sessions with a user. These sessions are established after the user has authenticated with username/passphrase credentials. The user can change their own passphrase, but this does not invalidate active sessions that the user may have with SAP Commerce Cloud web applications, which gives an attacker the opportunity to reuse old session credentials, resulting in Insufficient Session Expiration.

Vulnerable Configurations

Part Description Count
Application
Sap
4

Common Weakness Enumeration (CWE)