CWE-917 · 179 записей
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
CVE этого класса
179 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2022-26134Готовый эксплойт | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Критическая9,8 | KEV | 100,0 % | 3 июн. 2022 г. |
99Срочно | CVE-2021-26084Готовый эксплойт | In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attackatlassian · confluence data center · CWE-917 | Критическая9,8 | KEV | 100,0 % | 30 авг. 2021 г. |
98Срочно | CVE-2020-17530Готовый эксплойт | Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.apache · struts · CWE-917 | Критическая9,8 | KEV | 95,9 % | 10 дек. 2020 г. |
96Срочно | CVE-2021-45046Готовый эксплойт | Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attackapache · log4j · CWE-917 | Критическая9,0 | KEV | 100,0 % | 14 дек. 2021 г. |
95Срочно | CVE-2020-10199Готовый эксплойт | Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).sonatype · nexus · CWE-917 | Высокая8,8 | KEV | 99,1 % | 1 апр. 2020 г. |
90Срочно | CVE-2010-1871Готовый эксплойт | JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for redhat · jboss enterprise application platform · CWE-917 | Высокая8,8 | KEV | 83,4 % | 5 авг. 2010 г. |
65На этой неделе | CVE-2021-31805Proof of concept | Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.apache · struts · CWE-917 | Критическая9,8 | — | 85,4 % | 12 апр. 2022 г. |
46В плане | CVE-2019-5355Эксплойта нет | A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | Высокая7,5 | — | 54,0 % | 5 июн. 2019 г. |
45В плане | CVE-2018-12533Proof of concept | JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitredhat · richfaces · CWE-917 | Критическая9,8 | — | 19,0 % | 18 июн. 2018 г. |
44В плане | CVE-2022-22980Proof of concept | A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expresvmware · spring data mongodb · CWE-917 | Критическая9,8 | — | 17,8 % | 23 июн. 2022 г. |
41В плане | CVE-2020-3956Proof of concept | VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly hanvmware · vcloud director · CWE-917 | Высокая8,8 | — | 21,1 % | 20 мая 2020 г. |
41В плане | CVE-2019-5352Эксплойта нет | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | Критическая9,8 | — | 8,1 % | 5 июн. 2019 г. |
41В плане | CVE-2019-11949Эксплойта нет | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | Критическая9,8 | — | 8,1 % | 5 июн. 2019 г. |
41В плане | CVE-2019-5358Эксплойта нет | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | Критическая9,8 | — | 8,1 % | 5 июн. 2019 г. |
41В плане | CVE-2019-5387Эксплойта нет | A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.hp · intelligent management center · CWE-917 | Критическая9,8 | — | 8,1 % | 5 июн. 2019 г. |
41В плане | CVE-2018-12532Эксплойта нет | JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapperredhat · richfaces · CWE-917 | Критическая9,8 | — | 7,0 % | 18 июн. 2018 г. |
41В плане | CVE-2020-7169Эксплойта нет | A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Centerhp · intelligent management center · CWE-917 | Критическая9,8 | — | 7,0 % | 19 окт. 2020 г. |
41В плане | CVE-2020-7161Эксплойта нет | A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMhp · intelligent management center · CWE-917 | Критическая9,8 | — | 7,0 % | 19 окт. 2020 г. |
41В плане | CVE-2020-7153Эксплойта нет | A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMhp · intelligent management center · CWE-917 | Критическая9,8 | — | 7,0 % | 19 окт. 2020 г. |
41В плане | CVE-2020-7151Эксплойта нет | A faulttrapgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Centerhp · intelligent management center · CWE-917 | Критическая9,8 | — | 7,0 % | 19 окт. 2020 г. |
41В плане | CVE-2020-24652Эксплойта нет | A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center hp · intelligent management center · CWE-917 | Критическая9,8 | — | 7,0 % | 19 окт. 2020 г. |
41В плане | CVE-2020-7168Эксплойта нет | A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMChp · intelligent management center · CWE-917 | Критическая9,8 | — | 7,0 % | 19 окт. 2020 г. |
41В плане | CVE-2020-7141Эксплойта нет | A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMChp · intelligent management center · CWE-917 | Критическая9,8 | — | 7,0 % | 19 окт. 2020 г. |
41В плане | CVE-2020-7145Эксплойта нет | A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)hp · intelligent management center · CWE-917 | Критическая9,8 | — | 7,0 % | 19 окт. 2020 г. |
41В плане | CVE-2020-7147Эксплойта нет | A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center hp · intelligent management center · CWE-917 | Критическая9,8 | — | 7,0 % | 19 окт. 2020 г. |
- CVE-2022-2613499Срочно
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center3 июн. 2022 г.
- CVE-2021-2608499Срочно
In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence data center30 авг. 2021 г.
- CVE-2020-1753098Срочно
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 96 %apache · struts10 дек. 2020 г.
- CVE-2021-4504696Срочно
Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %apache · log4j14 дек. 2021 г.
- CVE-2020-1019995Срочно
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 99 %sonatype · nexus1 апр. 2020 г.
- CVE-2010-187190Срочно
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 83 %redhat · jboss enterprise application platform5 авг. 2010 г.
- CVE-2021-3180565На этой неделе
Forced OGNL evaluation, when evaluated on raw not validated user input in tag attributes, may lead to RCE.
КритическаяCVSS 9,8Proof of conceptEPSS 85 %apache · struts12 апр. 2022 г.
- CVE-2019-535546В плане
A remote denial of service vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
ВысокаяCVSS 7,5Эксплойта нетEPSS 54 %hp · intelligent management center5 июн. 2019 г.
- CVE-2018-1253345В плане
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbit
КритическаяCVSS 9,8Proof of conceptEPSS 19 %redhat · richfaces18 июн. 2018 г.
- CVE-2022-2298044В плане
A Spring Data MongoDB application is vulnerable to SpEL Injection when using @Query or @Aggregation-annotated query methods with SpEL expres
КритическаяCVSS 9,8Proof of conceptEPSS 18 %vmware · spring data mongodb23 июн. 2022 г.
- CVE-2020-395641В плане
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly han
ВысокаяCVSS 8,8Proof of conceptEPSS 21 %vmware · vcloud director20 мая 2020 г.
- CVE-2019-535241В плане
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %hp · intelligent management center5 июн. 2019 г.
- CVE-2019-1194941В плане
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %hp · intelligent management center5 июн. 2019 г.
- CVE-2019-535841В плане
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %hp · intelligent management center5 июн. 2019 г.
- CVE-2019-538741В плане
A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.
КритическаяCVSS 9,8Эксплойта нетEPSS 8 %hp · intelligent management center5 июн. 2019 г.
- CVE-2018-1253241В плане
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %redhat · richfaces18 июн. 2018 г.
- CVE-2020-716941В плане
A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · intelligent management center19 окт. 2020 г.
- CVE-2020-716141В плане
A reporttaskselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iM
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · intelligent management center19 окт. 2020 г.
- CVE-2020-715341В плане
A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iM
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · intelligent management center19 окт. 2020 г.
- CVE-2020-715141В плане
A faulttrapgroupselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · intelligent management center19 окт. 2020 г.
- CVE-2020-2465241В плане
A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · intelligent management center19 окт. 2020 г.
- CVE-2020-716841В плане
A selectusergroup expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · intelligent management center19 окт. 2020 г.
- CVE-2020-714141В плане
A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · intelligent management center19 окт. 2020 г.
- CVE-2020-714541В плане
A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC)
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · intelligent management center19 окт. 2020 г.
- CVE-2020-714741В плане
A deployselectbootrom expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center
КритическаяCVSS 9,8Эксплойта нетEPSS 7 %hp · intelligent management center19 окт. 2020 г.