CVE-2025-3322

An improper neutralization of inputs used in expression
language allows remote code execution with the highest privileges on the
server.
Expression Language Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
UNKNOWN
---
B.BraunCNA
---
---
CISA-ADPADP
---
---