Back to overview

CVE-2021-27602

CRITICAL
9.9
CVSS 3.0
Description
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker with this authorization can inject malicious code in the source rules and perform remote code execution enabling them to compromise the confidentiality, integrity and availability of the application.

Metadata

CVE ID
CVE-2021-27602
State
PUBLISHED
Assigner
sap
Reserved
2021-02-23 00:00 UTC
Published
2021-04-13 18:41 UTC
Last updated
2024-08-03 21:26 UTC
Vendor / Product
SAP SE / SAP Commerce
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
SAP SE SAP Commerce < 1808, < 1811, < 1905, < 2005 …
Weakness (CWE)
CWESourceDescription
cna Code Injection
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview