CVE-2021-27602

SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker with this authorization can inject malicious code in the source rules and perform remote code execution enabling them to compromise the confidentiality, integrity and availability of the application.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:commerce:1808:*:*:*:*:*:*:*
cpe:2.3:a:sap:commerce:1811:*:*:*:*:*:*:*
cpe:2.3:a:sap:commerce:1905:*:*:*:*:*:*:*
cpe:2.3:a:sap:commerce:2005:*:*:*:*:*:*:*
cpe:2.3:a:sap:commerce:2011:*:*:*:*:*:*:*

History

21 Nov 2024, 05:58

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/3040210 - Permissions Required () https://launchpad.support.sap.com/#/notes/3040210 - Permissions Required
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649 - Vendor Advisory

Information

Published : 2021-04-13 19:15

Updated : 2024-11-21 05:58


NVD link : CVE-2021-27602

Mitre link : CVE-2021-27602

CVE.ORG link : CVE-2021-27602


JSON object : View

Products Affected

sap

  • commerce
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')