AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-6302

HIGH · CVSS 8.1 EPSS 0.80%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-09-09 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.1. It affects Office.

CVE
CVE-2020-6302
Severity
HIGH
CVSS
8.1
EPSS
0.80%
Office

Original NVD Description

SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.

Related CVEs

Other vulnerabilities affecting the same vendor(s)