← Back to browse · API

CVE-2021-21477

Severity
CRITICAL
CVSS
9.9
EPSS
0.29847
Risk score
50.05
CISA KEV
No
PoC
No
Published
2021-02-09
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-8751, GHSA-JG2G-JQ85-V7JW
Products
SAP_SE:SAP Commerce < 1808, SAP_SE:SAP Commerce < 1811, SAP_SE:SAP Commerce < 1905, SAP_SE:SAP Commerce < 2005, SAP_SE:SAP Commerce < 2011
Sources
euvd EUVD-2021-8751

Description

SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution vulnerability enabling the attacker to compromise the underlying host enabling him to impair confidentiality, integrity and availability of the application.

References