CVE-2021-21445

5.4MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 January 2021

Summary

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.

Affected Version(s)

SAP Commerce Cloud < 1808 < 1808

SAP Commerce Cloud < 1811 < 1811

SAP Commerce Cloud < 1905 < 1905

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.