CVE-2020-17530
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Apache Struts Remote Code Execution Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 96% (אחוזון 100) נכון ל-30/7/2026
- CWE
- CWE-917
מוצרים מושפעים
apache: struts; oracle: business intelligence; oracle: communications diameter intelligence hub; oracle: communications policy management; oracle: communications pricing design center; oracle: financial services data integration hub; oracle: hospitality opera 5; oracle: mysql enterprise monitor
קישורים
- https://cwiki.apache.org/confluence/display/WW/S2-061 Vendor Advisory
- https://cwiki.apache.org/confluence/display/WW/S2-061 Vendor Advisory
- https://security.netapp.com/advisory/ntap-20210115-0005/ PatchThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html PatchThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210115-0005/ PatchThird Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory