CVE-2021-21477 Information
Jun 07, 2022
cve
Description
SAP Commerce Cloud versions - 18081811190520052011 enables certain users with required privileges to edit drools rules an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution vulnerability enabling the attacker to compromise the underlying host enabling him to impair confidentiality integrity and availability of the application.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Reference
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=568460543 https://launchpad.support.sap.com/#/notes/3014121
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.9
Share on: