← العودة للجدول
CVE-2021-42064
CVE-2021-42064 — If configured to use an Oracle database and if a query is created using the flex
📅 2021-12-14
🔴 Critical 🔥 No NVD Exploit Oracle CVSS 9.8 🎯 EPSS 0.62%

📋 الوصف الكامل

If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The vulnerability is present if the parameterized "in" clause accepts more than 1000 values.

💻 الأنظمة المتأثرة

Java | Oracle Database | SAP

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2021-42064

📡 المصدر

NVD

✅ الحلول والتخفيف

Refer to CVE-2021-42064 NVD advisory

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←