CVE-2021-21445: Input Validation
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-21445.
What is the severity of CVE-2021-21445?
The severity of CVE-2021-21445 is medium with a severity value of 5.4.
Which versions of SAP Commerce Cloud are affected by CVE-2021-21445?
SAP Commerce Cloud versions 1808, 1811, 1905, 2005, and 2011 are affected by CVE-2021-21445.
How does CVE-2021-21445 impact the system?
CVE-2021-21445 allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, potentially leading to advanced attacks.
Is there a fix available for CVE-2021-21445?
Yes, you can find the fix available for CVE-2021-21445 in the references provided.