Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9wr2-hqp2-7rf5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.

SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.

EPSS

Процентиль: 65%
0.00485
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
больше 6 лет назад

SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.

CVSS3: 8.8
fstec
больше 6 лет назад

Уязвимость компонента Mediaconversion платформы электронной коммерции SAP Commerce Cloud, позволяющая нарушителю получить полный контроль над приложением

EPSS

Процентиль: 65%
0.00485
Низкий

8.8 High

CVSS3

Дефекты

CWE-94