CVE-2020-17530: Apache Struts Remote Code Execution Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 95.9% chance of exploitation in the next 30 days.
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Affected products
- Apache Struts: from 2.0.0, before 2.5.30 (fixed in 2.5.30)
- Oracle Business Intelligence: version 12.2.1.3.0 only; version 12.2.1.4.0 only
- Oracle Communications Diameter Intelligence Hub: version 8.0.0 only; version 8.1.0 only; version 8.2.0 only; version 8.2.3 only
- Oracle Communications Policy Management: version 12.5.0 only
- Oracle Communications Pricing Design Center: version 12.0.0.3.0 only
- Oracle Financial Services Data Integration Hub: version 8.0.3 only; version 8.0.6 only
- Oracle Hospitality Opera 5: version 5.6 only
- Oracle MySQL Enterprise Monitor: version 8.0.23 only
Published 2020-12-11. Last modified 2026-06-17.