CVE-2021-21477
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution vulnerability enabling the attacker to compromise the underlying host enabling him to impair confidentiality, integrity and availability of the application.
SAP Commerce Cloud, versiones - 1808,1811,1905,2005,2011, permite a determinados usuarios con privilegios requeridos editar las reglas de drools, un atacante autenticado con este privilegio podrá inyectar código malicioso en las reglas de drools que, cuando se ejecutan, conllevan a una vulnerabilidad de ejecución de código remota permitiendo al atacante poner en peligro el host subyacente, permitiendo afectar la confidencialidad, integridad y disponibilidad de la aplicación
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-12-30 CVE Reserved
- 2021-02-09 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=568460543 | 2021-02-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Commerce Search vendor "Sap" for product "Commerce" | 1808 Search vendor "Sap" for product "Commerce" and version "1808" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Commerce Search vendor "Sap" for product "Commerce" | 1811 Search vendor "Sap" for product "Commerce" and version "1811" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Commerce Search vendor "Sap" for product "Commerce" | 1905 Search vendor "Sap" for product "Commerce" and version "1905" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Commerce Search vendor "Sap" for product "Commerce" | 2005 Search vendor "Sap" for product "Commerce" and version "2005" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Commerce Search vendor "Sap" for product "Commerce" | 2011 Search vendor "Sap" for product "Commerce" and version "2011" | - |
Affected
|