PT-2021-2218 · Sap · Sap Commerce Cloud
Published
2021-02-09
·
Updated
2021-02-16
·
CVE-2021-21477
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Commerce Cloud versions 1808 through 2011
Description
The issue is related to errors in code generation management, allowing an authenticated attacker with required privileges to inject malicious code in drools rules, leading to Remote Code Execution. This enables the attacker to compromise the underlying host, impairing confidentiality, integrity, and availability of the application.
Recommendations
For SAP Commerce Cloud versions 1808 through 2011, consider restricting access to editing drools rules to minimize the risk of exploitation. As a temporary workaround, disabling the editing of drools rules for users with required privileges may help until a patch is available.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Commerce Cloud