CVE-2021-27619
published 2021-05-11CVE-2021-27619: SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.82%
53.0th percentile
SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the user can iteratively enter one character at a time to search and determine the masked attribute value thereby leading to information disclosure.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | commerce | — | — |
| sap | commerce | — | — |
| sap | commerce | — | — |
| sap | commerce | — | — |
| sap | commerce | — | — |
| sap_se | sap_commerce | < 1808 | 1808 |
| sap_se | sap_commerce | < 1811 | 1811 |
| sap_se | sap_commerce | < 1905 | 1905 |
| sap_se | sap_commerce | < 2005 | 2005 |
| sap_se | sap_commerce | < 2011 | 2011 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
osv9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wcj9-7cp9-cw82: SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not suppose
ghsa_unreviewed·2022-05-24
CVE-2021-27619 [MEDIUM] CWE-20 GHSA-wcj9-7cp9-cw82: SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not suppose
SAP Commerce (Backoffice Search), versions - 1808, 1811, 1905, 2005, 2011, allows a low privileged user to search for attributes which are not supposed to be displayed to them. Although the search results are masked, the user can iteratively enter one character at a time to search and determine the masked attribute value thereby leading to information disclosure.
OSV
python2.7 vulnerability
osv·2022-02-08·CVSS 9.8
CVE-2021-3177 python2.7 vulnerability
python2.7 vulnerability
USN-4754-1 fixed vulnerabilities in Python. Because of a regression, a
subsequent update removed the fix for CVE-2021-3177. This update reinstates
the security fix for CVE-2021-3177 in Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2020-27619, CVE-2021-3177)
OSV
python2.7 vulnerability
osv·2021-03-03·CVSS 9.8
CVE-2021-3177 python2.7 vulnerability
python2.7 vulnerability
USN-4754-1 fixed vulnerabilities in Python. Because of a regression, a
subsequent update removed the fix for CVE-2021-3177. This update reinstates
the security fix for CVE-2021-3177.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2020-27619, CVE-2021-3177)
OSV
python2.7 regression
osv·2021-02-25·CVSS 9.8
CVE-2021-3177 python2.7 regression
python2.7 regression
USN-4754-1 fixed a vulnerability in Python. The fix for CVE-2021-3177 introduced a
regression in Python 2.7. This update reverts the security fix pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2020-27619, CVE-2021-3177)
OSV
python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
osv·2021-02-25·CVSS 9.8
CVE-2020-27619 python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
python2.7, python3.4, python3.5, python3.6, python3.8 vulnerabilities
It was discovered that Python incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code
or cause a denial of service. (CVE-2020-27619, CVE-2021-3177)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-05-11
Published