In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
References
Link | Resource |
---|---|
https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c | Third Party Advisory |
Configurations
Information
Published : 2021-02-09 13:15
Updated : 2021-02-16 09:33
NVD link : CVE-2021-21479
Mitre link : CVE-2021-21479
JSON object : View
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
Products Affected
sap
- scimono