CVE-2021-21477 is a critical Remote Code Execution (RCE) vulnerability affecting SAP Commerce Cloud versions 1808, 1811, 1905, 2005, and 2011. It allows authenticated attackers with specific privileges to inject malicious code into Drools rules, leading to the compromise of the underlying host and impacting confidentiality, integrity, and availability. With a CVSS score of 9.9, this vulnerability is considered critical due to its low attack complexity and severe potential impact. While no public exploit intelligence like Metasploit or ExploitDB entries are available, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1808CPE matchmatch criteria | cpe:2.3:a:sap:commerce:1808:*:*:*:*:*:*:* | ||
1811CPE matchmatch criteria | cpe:2.3:a:sap:commerce:1811:*:*:*:*:*:*:* | ||
1905CPE matchmatch criteria | cpe:2.3:a:sap:commerce:1905:*:*:*:*:*:*:* | ||
2005CPE matchmatch criteria | cpe:2.3:a:sap:commerce:2005:*:*:*:*:*:*:* | ||
2011CPE matchmatch criteria | cpe:2.3:a:sap:commerce:2011:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.