<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 15:40:23 +0000</lastBuildDate>
    <item>
      <title>certfr-2020-avi-549 — De multiples vulnérabilités ont été découvertes dans les produits SAP.
Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-549</link>
      <description>certfr-2020-avi-549</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-549</guid>
    </item>
    <item>
      <title>cnvd-2020-65569</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-65569</link>
      <description>cnvd-2020-65569</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-65569</guid>
    </item>
    <item>
      <title>EUVD-2026-37236</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-37236</link>
      <description>EUVD-2026-37236</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-37236</guid>
    </item>
    <item>
      <title>fkie_cve-2020-6302</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-6302</link>
      <description>&lt;p&gt;SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-6302</guid>
    </item>
    <item>
      <title>GHSA-m697-r4gm-82f3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m697-r4gm-82f3</link>
      <description>&lt;p&gt;SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;SAP Commerce versions 6.7, 1808, 1811, 1905, 2005 contains the jSession ID in the backoffice URL when the application is loaded initially. An attacker can get this session ID via shoulder surfing or man in the middle attack and subsequently get access to admin user accounts, leading to Session Fixation and complete compromise of the confidentiality, integrity and availability of the application.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m697-r4gm-82f3</guid>
    </item>
    <item>
      <title>gsd-2020-6302</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-6302</link>
      <description>gsd-2020-6302</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-6302</guid>
    </item>
  </channel>
</rss>
