Tracker / CVE-2020-17530
CVE-2020-17530
Exploited Critical 9.8
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Affected products and versions
| apache | struts · 2.0.0 → 2.5.30 |
|---|---|
| oracle | business_intelligence |
| oracle | communications_diameter_intelligence_hub |
| oracle | communications_policy_management |
| oracle | communications_pricing_design_center |
| oracle | financial_services_data_integration_hub |
| oracle | hospitality_opera_5 |
| oracle | mysql_enterprise_monitor |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.