CWE-917
204 CVEs • Abstraction: Base
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
CVEs (204)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The fix issued for CVE-2020-17530 was incomplete. So from Apache Struts 2.0.0 to 2.5.29, still some of the tag’s attributes could perform a double evaluation if a developer applied forced OGNL evaluation by using the %{....Show more |
2Oracle Vmware28Banking Branch Banking Cash ManagementBanking Corporate Lending Process Management+25 moreJun 17, 2026 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in rem...Show more |
2Oracle Vmware10Commerce Guided Search Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Console+7 moreJun 17, 2026 Mar 3, 2022 N/A· v4 10.0 CRITICAL· v3 6.8 MEDIUM· v2 In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a ma...Show more |
7Apache CvatDebian+4 more556bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+52 moreJun 17, 2026 Dec 14, 2021 N/A· v4 9.0 CRITICAL· v3 5.1 MEDIUM· v2 It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the...Show more |
12Apache AppleBentley+9 more1436bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+140 moreJun 17, 2026 Dec 10, 2021 N/A· v4 10.0 CRITICAL· v3 9.3 HIGH· v2 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other J...Show more |
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Aug 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists that would allow an unauthenticated attacker to execute arbitrary code on a Confluence Server or Data Center instance. The...Show more |
ObjectPlanet Opinio before 7.14 allows Expression Language Injection via the admin/permissionList.do from parameter. This can be used to retrieve possibly sensitive serverInfo data. |
3Eclipse OracleQuarkus4Communications Cloud Native Core Policy Jakarta Expression LanguageQuarkus+1 moreJun 17, 2026 May 26, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid. |
2Apache Oracle8Business Intelligence Communications Diameter Intelligence HubCommunications Policy Management+5 moreJun 17, 2026 Dec 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25. |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A iccselectrules expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A perfaddormoddevicemonitor expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A ictexpertcsvdownload expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A devicethresholdconfig expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A devsoftsel expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A deviceselect expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A faultflasheventselectfact expression language injectionremote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A userselectpagingcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A reportpage index expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |
1Hp 1Intelligent Management Center Jun 17, 2026 Oct 19, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A powershellconfigcontent expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). |