cbcvebase.
CVE-2021-21445
published 2021-01-12

CVE-2021-21445: SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.

Affected

10 ranges
VendorProductVersion rangeFixed in
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sapcommerce_cloud
sap_sesap_commerce_cloud< 18081808
sap_sesap_commerce_cloud< 18111811
sap_sesap_commerce_cloud< 19051905
sap_sesap_commerce_cloud< 20052005
sap_sesap_commerce_cloud< 20112011