SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker with this authorization can inject malicious code in the source rules and perform remote code execution enabling them to compromise the confidentiality, integrity and availability of the application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2021-04-13T18:41:24
Updated: 2024-08-03T21:26:10.373Z
Reserved: 2021-02-23T00:00:00
Link: CVE-2021-27602
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-04-13T19:15:15.320
Modified: 2024-11-21T05:58:16.560
Link: CVE-2021-27602
Redhat
No data.