CVE-2020-17530: Apache Struts Remote Code Execution Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 95.9% chance of exploitation in the next 30 days.

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

Affected products

  • Apache Struts: from 2.0.0, before 2.5.30 (fixed in 2.5.30)
  • Oracle Business Intelligence: version 12.2.1.3.0 only; version 12.2.1.4.0 only
  • Oracle Communications Diameter Intelligence Hub: version 8.0.0 only; version 8.1.0 only; version 8.2.0 only; version 8.2.3 only
  • Oracle Communications Policy Management: version 12.5.0 only
  • Oracle Communications Pricing Design Center: version 12.0.0.3.0 only
  • Oracle Financial Services Data Integration Hub: version 8.0.3 only; version 8.0.6 only
  • Oracle Hospitality Opera 5: version 5.6 only
  • Oracle MySQL Enterprise Monitor: version 8.0.23 only

Published 2020-12-11. Last modified 2026-06-17.