Advisory
A note with CVSS 9.3 for component CEC-COM-CPS was released by SAP on 14.04.2020. The correction/advisory 2904480 was described with "[CVE-2020-6238] Missing XML Validation vulnerability in SAP Commerce" and affects the system type SAP Commerce Cloud.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is external entity tunneling (xxe) within SAP Commerce Cloud.
Risk specification
SAP Commerce does not sufficiently validate an XML document which affects confidentiality and availability (partially) of SAP Commerce.
Solution
SAP Commerce has been updated to correctly validate XML input
