VYPR

scimono

by SAP

CVEs (2)

  • CVE-2021-21479CriFeb 9, 2021
    risk 0.53cvss 9.1epss 0.10

    In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.

  • CVE-2021-33668HigJun 9, 2021
    risk 0.49cvss 7.5epss 0.01

    Due to improper input sanitization, specially crafted LDAP queries can be injected by an unauthenticated user. This could partially impact the confidentiality of the application.