CVE-2021-27602 Information

Description

SAP Commerce versions - 1808 1811 1905 2005 2011 Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker with this authorization can inject malicious code in the source rules and perform remote code execution enabling them to compromise the confidentiality integrity and availability of the application.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Reference

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649 https://launchpad.support.sap.com/#/notes/3040210

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.9

Share on: