Back to search
CVE-2021-42064
Published: Dec 14, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The vulnerability is present if the parameterized "in" clause accepts more than 1000 values.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP Commerce | affected < 1905affected < 2005affected < 2105affected < 2011 |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now