OSV 1.4.0 · unreviewed · 修改于 2021-12-17 08:00
发布时间
2021-12-15 08:00
GitHub 审查时间
—
NVD 发布时间
2021-12-15 00:15
源文件
advisories/unreviewed/2021/12/GHSA-529g-jxw5-837v/GHSA-529g-jxw5-837v.json
If configured to use an Oracle database and if a query is created using the flexible search java api with a parameterized "in" clause, SAP Commerce - versions 1905, 2005, 2105, 2011, allows attacker to execute crafted database queries, exposing backend database. The vulnerability is present if the parameterized "in" clause accepts more than 1000 values.
该公告没有提供结构化的受影响软件包信息。