CWE-917
204 CVEs • Abstraction: Base
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
CVEs (204)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A chooseperfview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A comparefilesresult expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A faultdevparasset expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A eventinfo_content expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A adddevicetoview expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A addvsiinterfaceinfo expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A syslogtempletselectwin expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A legend expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows the...Show more |
In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, rrequest parameters injected inside an expression evaluated by `symfony/expression-language` package haven't been sanitized properly. This allows th...Show more |
Netflix Titus, all versions prior to version v0.1.1-rc.274, uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are...Show more |
Netflix Titus uses Java Bean Validation (JSR 380) custom constraint validators. When building custom constraint violation error messages, different types of interpolation are supported, including Java EL expressions. If...Show more |
VMware Cloud Director 10.0.x before 10.0.0.2, 9.7.0.x before 9.7.0.5, 9.5.0.x before 9.5.0.6, and 9.1.0.x before 9.1.0.4 do not properly handle input leading to a code injection vulnerability. An authenticated actor may...Show more |
A Server-Side Template Injection was identified in Apache Syncope prior to 2.1.6 enabling attackers to inject arbitrary Java EL expressions, leading to an unauthenticated Remote Code Execution (RCE) vulnerability. Apache...Show more |
Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2). |
An issue was discovered in FusionAuth before 1.11.0. An authenticated user, allowed to edit e-mail templates (Home -> Settings -> Email Templates) or themes (Home -> Settings -> Themes), can execute commands on the under...Show more |
Adobe Experience Manager versions 6.5, 6.4, 6.3, 6.2, 6.1, and 6.0 have an expression language injection vulnerability. Successful exploitation could lead to sensitive information disclosure. |
In http.c in Embedthis GoAhead before 4.1.1 and 5.x before 5.0.1, a header parsing vulnerability causes a memory assertion, out-of-bounds memory reference, and potential DoS, as demonstrated by a colon on a line by itsel...Show more |
1Hp 1Intelligent Management Center Jun 17, 2026 Jun 5, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. |
1Hp 1Intelligent Management Center Jun 17, 2026 Jun 5, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A remote code execution vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09. |