{"id":"GHSA-29q4-gxjq-rx5c","summary":"Remote Code Execution in SCIMono","details":"### Impact\nIt is possible for attacker to inject and execute java expression and compromising the availability and integrity of the system.\n\n### Patches\nThe issue was fixed on  [0.0.19 version](https://mvnrepository.com/artifact/com.sap.scimono/scimono-server/0.0.19)","aliases":["CVE-2021-21479"],"modified":"2026-05-04T08:46:02.865215749Z","published":"2021-02-10T02:31:53Z","database_specific":{"github_reviewed_at":"2021-02-10T01:48:45Z","nvd_published_at":"2021-02-09T21:15:00Z","cwe_ids":["CWE-59","CWE-62","CWE-690","CWE-74","CWE-77","CWE-917"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/SAP/scimono/security/advisories/GHSA-29q4-gxjq-rx5c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21479"},{"type":"WEB","url":"https://github.com/SAP/scimono/commit/413b5d75fa94e77876af0e47be76475a23745b80"},{"type":"WEB","url":"https://mvnrepository.com/artifact/com.sap.scimono/scimono-server/0.0.19"}],"affected":[{"package":{"name":"com.sap.scimono:scimono-server","ecosystem":"Maven","purl":"pkg:maven/com.sap.scimono/scimono-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.0.19"}]}],"versions":["0.0.1","0.0.11","0.0.12","0.0.13","0.0.14","0.0.15","0.0.16","0.0.17","0.0.18","0.0.2","0.0.3","0.0.4","0.0.5","0.0.6","0.0.7","0.0.8","0.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/02/GHSA-29q4-gxjq-rx5c/GHSA-29q4-gxjq-rx5c.json"}}],"schema_version":"1.9.0"}