Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-11975

Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.39
EPSS Ranking 97.1%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
Products affected by CVE-2020-11975
  • Apache » Unomi » Version: 1.3.0
    cpe:2.3:a:apache:unomi:1.3.0
  • Apache » Unomi » Version: 1.4.0
    cpe:2.3:a:apache:unomi:1.4.0
  • Apache » Unomi » Version: 1.5.0
    cpe:2.3:a:apache:unomi:1.5.0


Contact Us

Shodan ® - All rights reserved