cbcvebase.
CVE-2021-21477
published 2021-02-09

CVE-2021-21477: SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with…

PriorityP275critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
29.85%
98.0th percentile
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the drools rules which when executed leads to Remote Code Execution vulnerability enabling the attacker to compromise the underlying host enabling him to impair confidentiality, integrity and availability of the application.

Affected

10 ranges
VendorProductVersion rangeFixed in
sapcommerce
sapcommerce
sapcommerce
sapcommerce
sapcommerce
sap_sesap_commerce< 18081808
sap_sesap_commerce< 18111811
sap_sesap_commerce< 19051905
sap_sesap_commerce< 20052005
sap_sesap_commerce< 20112011

Detection & IOCsextracted from sources · hover to see the quote

  • Authenticated attacker with drools rule editing privileges can inject malicious code into drools rules to achieve Remote Code Execution on SAP Commerce Cloud
  • ·Vulnerability affects SAP Commerce Cloud versions 1808, 1811, 1905, 2005, and 2011 only
  • ·Exploitation requires authentication and specific drools rule editing privileges — not exploitable by unauthenticated or low-privileged users

CVSS provenance

nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv3.09.9CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.