Vulnerability Details CVE-2021-21445
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.8%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2021-21445
-
cpe:2.3:a:sap:commerce_cloud:1808
-
cpe:2.3:a:sap:commerce_cloud:1811
-
cpe:2.3:a:sap:commerce_cloud:1905
-
cpe:2.3:a:sap:commerce_cloud:2005
-
cpe:2.3:a:sap:commerce_cloud:2011