← All CVEs

CVE-2020-17530

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

9.8
CVSS
95.9%
EPSS (exploit prob.)
100th
EPSS percentile
2020-12-11
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-917

Affected products

VendorProductAffected versions
apachestruts>= 2.0.0, < 2.5.30
oraclebusiness_intelligence12.2.1.3.0
oraclebusiness_intelligence12.2.1.4.0
oraclecommunications_diameter_intelligence_hub8.0.0
oraclecommunications_diameter_intelligence_hub8.1.0
oraclecommunications_diameter_intelligence_hub8.2.0
oraclecommunications_diameter_intelligence_hub8.2.3
oraclecommunications_policy_management12.5.0
oraclecommunications_pricing_design_center12.0.0.3.0
oraclefinancial_services_data_integration_hub8.0.3
oraclefinancial_services_data_integration_hub8.0.6
oraclehospitality_opera_55.6
oraclemysql_enterprise_monitor8.0.23

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-17530