HIGH · 8.8

CVE-2020-13936

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This appli...

Vulnerability Description

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ApacheVelocity Engine< 2.3
ApacheWss4J2.3.1
DebianDebian Linux9.0
OracleBanking Deposits And Lines Of Credit Servicing2.12.0
OracleBanking Enterprise Default Management>= 2.3.0, <= 2.4.1
OracleBanking Loans Servicing2.12.0
OracleBanking Party Management2.7.0
OracleBanking Platform>= 2.3.0, <= 2.4.1
OracleCommunications Cloud Native Core Policy1.14.0
OracleCommunications Network Integrity7.3.6
OracleHospitality Token Proxy Service19.2
OracleRetail Integration Bus19.0.1
OracleRetail Order Broker16.0
OracleRetail Service Backbone19.0.1
OracleRetail Xstore Office Cloud Service16.0.6
OracleUtilities Testing Accelerator6.0.0.1.1

References

FAQ

What is CVE-2020-13936?

CVE-2020-13936 is a vulnerability with a CVSS score of 8.8 (HIGH). An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This appli...

How severe is CVE-2020-13936?

CVE-2020-13936 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-13936?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Velocity Engine, Apache Wss4J, Debian Debian Linux, Oracle Banking Deposits And Lines Of Credit Servicing, Oracle Banking Enterprise Default Management.