Medium severity5.4NVD Advisory· Published Jan 12, 2021· Updated Jun 17, 2026
CVE-2021-21445
CVE-2021-21445
Description
SAP Commerce Cloud, versions - 1808, 1811, 1905, 2005, 2011, allows an authenticated attacker to include invalidated data in the HTTP response Content Type header, due to improper input validation, and sent to a Web user. A successful exploitation of this vulnerability may lead to advanced attacks, including cross-site scripting and page hijacking.
Affected products
71808, 1811, 1905, 2005, 2011+ 5 more
- (no CPE)range: 1808, 1811, 1905, 2005, 2011
- cpe:2.3:a:sap:commerce_cloud:1808:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:1811:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:1905:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:2005:*:*:*:*:*:*:*
- cpe:2.3:a:sap:commerce_cloud:2011:*:*:*:*:*:*:*
- SAP SE/SAP Commerce Cloudv5Range: < 1808
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.