CyberSec.Space Logo
返回 CVE 瀏覽器

CVE-2020-17530

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score83.0710%
EPSS Percentile85.96th
Published2020年12月11日
Last Modified2025年10月27日

Vulnerability Description

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

Affected Platforms (CPE)

📦
Apache

Struts

>= 2.0.0 and < 2.5.30
📦
Oracle

Business Intelligence

= 12.2.1.3.0
📦
Oracle

Business Intelligence

= 12.2.1.4.0
📦
Oracle

Communications Diameter Intelligence Hub

= 8.0.0
📦
Oracle

Communications Diameter Intelligence Hub

= 8.1.0
📦
Oracle

Communications Diameter Intelligence Hub

= 8.2.0
📦
Oracle

Communications Diameter Intelligence Hub

= 8.2.3
📦
Oracle

Communications Policy Management

= 12.5.0
📦
Oracle

Communications Pricing Design Center

= 12.0.0.3.0
📦
Oracle

Financial Services Data Integration Hub

= 8.0.3
📦
Oracle

Financial Services Data Integration Hub

= 8.0.6
📦
Oracle

Hospitality Opera 5

= 5.6
📦
Oracle

Mysql Enterprise Monitor

= 8.0.23

References & Advisories

相關漏洞威脅