CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2020-17530

🔥 Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score83.0710%
EPSS Percentile85.96th
Published2020-12-11
Last Modified2025-10-27
Data SourcesNVDCISA KEVFIRST.org EPSS

Vulnerability Description

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

Affected Platforms (CPE)

📦
Apache

Struts

>= 2.0.0 and < 2.5.30
📦
Oracle

Business Intelligence

= 12.2.1.3.0= 12.2.1.4.0
📦
Oracle

Communications Diameter Intelligence Hub

= 8.0.0= 8.1.0= 8.2.0= 8.2.3
📦
Oracle

Communications Policy Management

= 12.5.0

References & Advisories

相關漏洞威脅