VulnerabilityModified
CVE-2021-21479
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
CRITICAL 9.1EPSS 10.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 10.12% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74
- Affected
- sap/scimono
- Source
- cna@sap.com
References
- https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5cThird Party Advisory
- https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5cThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.