{"id":"CVE-2021-21479","aliases":[],"url":"https://o3.security/vulnerability/CVE-2021-21479","summary":"Remote Code Execution in SCIMono","details":"### Impact\nIt is possible for attacker to inject and execute java expression and compromising the availability and integrity of the system.\n\n### Patches\nThe issue was fixed on  [0.0.19 version](https://mvnrepository.com/artifact/com.sap.scimono/scimono-server/0.0.19)","published":"2021-02-10T02:31:53Z","modified":"2026-05-04T08:46:02.865215749Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.sap.scimono:scimono-server","fixedVersion":"0.0.19"}],"fix":{"url":"https://github.com/SAP/scimono/commit/413b5d75fa94e77876af0e47be76475a23745b80","label":"SAP/scimono@413b5d7"},"references":[{"type":"WEB","url":"https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21479"},{"type":"WEB","url":"https://github.com/SAP/scimono/commit/413b5d75fa94e77876af0e47be76475a23745b80"},{"type":"WEB","url":"https://mvnrepository.com/artifact/com.sap.scimono/scimono-server/0.0.19"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-04T08:46:02.865215749Z"}}