SAP Commerce Cloud, versions- 1808,1811,1905,2005, allows an attacker to bypass existing authentication and permission checks via the '/medias' endpoint hence gaining access to Secure Media folders. This folder could contain sensitive files that results in disclosure of sensitive information and impact system configuration confidentiality.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571 | vendor advisory |
https://launchpad.support.sap.com/#/notes/2975189 | permissions required vendor advisory |
http://seclists.org/fulldisclosure/2021/Jun/27 | mailing list exploit third party advisory |
http://packetstormsecurity.com/files/163146/SAP-Hybris-eCommerce-Information-Disclosure.html | third party advisory |