3.5
CVSSv2

CVE-2021-21445

Published: 12/01/2021 Updated: 04/03/2021
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated malicious user to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sap commerce cloud 1808

sap commerce cloud 1811

sap commerce cloud 1905

sap commerce cloud 2005

sap commerce cloud 2011