CVE-2020-13936

EUVD-2022-0461
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
Affected Products (NVD)
VendorProductVersion
apachevelocity_engine
𝑥
< 2.3
apachewss4j
2.3.1
debiandebian_linux
9.0
oraclebanking_deposits_and_lines_of_credit_servicing
2.12.0
oraclebanking_enterprise_default_management
2.3.0 ≤
𝑥
≤ 2.4.1
oraclebanking_enterprise_default_management
2.6.2
oraclebanking_enterprise_default_management
2.7.1
oraclebanking_enterprise_default_management
2.10.0
oraclebanking_enterprise_default_management
2.12.0
oraclebanking_loans_servicing
2.12.0
oraclebanking_party_management
2.7.0
oraclebanking_platform
2.3.0 ≤
𝑥
≤ 2.4.1
oraclebanking_platform
2.6.2
oraclebanking_platform
2.7.1
oraclecommunications_cloud_native_core_policy
1.14.0
oraclecommunications_network_integrity
7.3.6
oraclehospitality_token_proxy_service
19.2
oracleretail_integration_bus
19.0.1
oracleretail_order_broker
16.0
oracleretail_service_backbone
19.0.1
oracleretail_xstore_office_cloud_service
16.0.6
oracleretail_xstore_office_cloud_service
17.0.4
oracleretail_xstore_office_cloud_service
18.0.3
oracleretail_xstore_office_cloud_service
19.0.2
oracleretail_xstore_office_cloud_service
20.0.1
oracleutilities_testing_accelerator
6.0.0.1.1
oracleutilities_testing_accelerator
6.0.0.2.2
oracleutilities_testing_accelerator
6.0.0.3.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
velocity
bookworm
1.7-6
fixed
bullseye
1.7-6
fixed
sid
1.7-7
fixed
trixie
1.7-7
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
velocity
bionic
Fixed 1.7-5ubuntu0.18.04.1~esm1
released
focal
Fixed 1.7-5+deb9u1build0.20.04.1
released
groovy
ignored
hirsute
ignored
impish
ignored
jammy
not-affected
kinetic
ignored
lunar
not-affected
trusty
dne
xenial
Fixed 1.7-4ubuntu0.1~esm1
released
References