github.com
https://github.com/SAP/scimono/commit/413b5d75fa94e77876af0e47be76475a23745b80 CVE-2021-21479
CRITICALNuclei
Remote Code Execution in SCIMono
Record summary
CVE-2021-21479 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Nov 30, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
3| Product | Source | Version range | Status |
|---|---|---|---|
scimonoBrowse SAP / scimono | VulnCheck | Version data not supplied | |
SCIMonoBrowse SAP SE / SCIMono | CVE List | < 0.0.19 | affected |
com.sap.scimono:scimono-serverBrowse Maven / com.sap.scimono:scimono-server | GitHub Advisory | Before 0.0.19 · Fixed in 0.0.19 | affected |
Nuclei templates
1ProjectDiscoveryCRITICALSCIMono <0.0.19 - Remote Code ExecutionCVSS 9.1
SCIMono before 0.0.19 is vulnerable to remote code execution because it is possible for an attacker to inject and execute java expressions and compromise the availability and integrity of the system.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.
Remediation
Upgrade SCIMono to version 0.0.19 or later to mitigate this vulnerability.
WeaknessesCWE-74
Authorsdwisiswant0
Template tagscvecve2021scimonorcesapvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CPE: cpe:2.3:a:sap:scimono:*:*:*:*:*:*:*:*
https://securitylab.github.com/advisories/GHSL-2020-227-scimono-ssti/ https://nvd.nist.gov/vuln/detail/CVE-2021-21479 https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
4github.comConfirmation
https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c mvnrepository.com
https://mvnrepository.com/artifact/com.sap.scimono/scimono-server/0.0.19 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-21479