CVE-2020-17530
π₯ Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
Vulnerability Description
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Affected Platforms (CPE)
π¦
Apache
Struts
>= 2.0.0 and < 2.5.30
π¦
Oracle
Business Intelligence
= 12.2.1.3.0= 12.2.1.4.0
π¦
Oracle
Communications Diameter Intelligence Hub
= 8.0.0= 8.1.0= 8.2.0= 8.2.3
π¦
Oracle
Communications Policy Management
= 12.5.0
