Session Fixation in SAP Commerce - CVE-2020-6302

 

Session Fixation in SAP Commerce - CVE-2020-6302

Published: September 11, 2020


Vulnerability identifier: #VU46639
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-6302
CWE-ID: CWE-384
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: SAP
Affected software:
SAP Commerce

Detailed vulnerability description

The vulnerability allows a remote attacker to compromise another user session.

The vulnerability exists due to improper session management mechanism. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.


How to mitigate CVE-2020-6302

Install updates from vendor's website.

Sources