Record summary

CVE-2021-21479 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.

Description

In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 30, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
CVE List< 0.0.19affected

com.sap.scimono:scimono-server

Browse Maven / com.sap.scimono:scimono-server
GitHub AdvisoryBefore 0.0.19 · Fixed in 0.0.19affected

Nuclei templates

1
ProjectDiscoveryCRITICALSCIMono <0.0.19 - Remote Code ExecutionCVSS 9.1

SCIMono before 0.0.19 is vulnerable to remote code execution because it is possible for an attacker to inject and execute java expressions and compromise the availability and integrity of the system.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.

Remediation

Upgrade SCIMono to version 0.0.19 or later to mitigate this vulnerability.

WeaknessesCWE-74
Authorsdwisiswant0
Template tagscvecve2021scimonorcesapvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CPE: cpe:2.3:a:sap:scimono:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

4