SAP Commerce, versions - 6.7, 1808, 1811, 1905, and SAP Commerce (Data Hub), versions - 6.7, 1808, 1811, 1905, allows an attacker to bypass the authentication and/or authorization that has been configured by the system administrator due to the use of Hardcoded Credentials.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://launchpad.support.sap.com/#/notes/2918924 | permissions required |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=547426775 | vendor advisory |