CVE-2021-21479
63Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actcvss 8.1epss 10%
from disclosure to weapon
Published on NVDFeb 9
VulnCheck+1024d
exploitation probability
10%top 5% of all CVEs
observed exploitation
yesVulnCheck
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Affected products
SAP SE · SCIMono