Critical severity9.1NVD Advisory· Published Feb 9, 2021· Updated Jun 17, 2026
CVE-2021-21479
CVE-2021-21479
Description
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.sap.scimono:scimono-serverMaven | < 0.0.19 | 0.0.19 |
Affected products
3- SAP SE/SCIMonov5Range: < 0.0.19
Patches
Vulnerability mechanics
References
5- github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5cnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-29q4-gxjq-rx5cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-21479ghsaADVISORY
- github.com/SAP/scimono/commit/413b5d75fa94e77876af0e47be76475a23745b80ghsaWEB
- mvnrepository.com/artifact/com.sap.scimono/scimono-server/0.0.19ghsaWEB
News mentions
0No linked articles in our index yet.