CVE-2021-21479
Remote Code Execution in SCIMono
EPSS 10.0%
Description
### Impact It is possible for attacker to inject and execute java expression and compromising the availability and integrity of the system. ### Patches The issue was fixed on [0.0.19 version](https://mvnrepository.com/artifact/com.sap.scimono/scimono-server/0.0.19)
How to fix CVE-2021-21479
To remediate CVE-2021-21479, upgrade the affected package to a fixed version below.
- Maven/com.sap.scimono:scimono-server—upgrade to 0.0.19 or later
Is CVE-2021-21479 being exploited?
Moderate — EPSS is 10.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.0.19