Loading
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.
Use CWE-611, Sap vendor hub and Commerce Cloud product page to widen CVE-2020-6238 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-39439, CVE-2023-42481 and CVE-2024-33003 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.