CVE-2021-21477
moderate-risk
Published 2021-02-09
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution vulnerability enabling the attacker to compromise the underlying host enabling him to impair confidentiality, integrity and availability of the application.
Do I need to act?
-
0.99% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.9/10
Critical
NETWORK
/ LOW complexity
Affected Products (5)
Commerce
Commerce
Commerce
Commerce
Commerce
Affected Vendors
References (4)
Permissions Required
https://launchpad.support.sap.com/#/notes/3014121
Permissions Required
https://launchpad.support.sap.com/#/notes/3014121
48
/ 100
moderate-risk
Severity
33/34 · Critical
Exploitability
3/34 · Minimal
Exposure
12/34 · Low