PT-2020-12962 · Apache · Apache Unomi

Published

2020-06-05

·

Updated

2025-07-21

·

CVE-2020-11975

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache Unomi (affected versions not specified)
Description The issue allows conditions to use OGNL scripting, which can call static Java classes from the JDK. This could potentially execute code with the permission level of the running Java process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2020-11975
GHSA-V6FQ-Q792-J46J

Affected Products

Apache Unomi