CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

180 vulnerabilities with CWE-917
CVE-2019-11955 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11954 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11953 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11952 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11951 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11949 CRITICAL
HPE IMC <7.3 - RCE
CVSS 9.8
CVE-2019-5389 HIGH
HPE IMC PLAT <7.3 E0506P09 - RCE
CVSS 8.8
CVE-2019-5388 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5387 CRITICAL
HPE IMC <7.3 - RCE
CVSS 9.8
CVE-2019-5386 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5385 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5384 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5383 HIGH
HPE Intelligent Management Center (IMC) PLAT <7.3 - RCE
CVSS 8.8
CVE-2019-5382 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5381 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5380 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5379 HIGH
HPE IMC PLAT <7.3 - RCE
CVSS 8.8
CVE-2019-5378 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5377 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5373 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5372 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5371 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5370 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5366 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5365 HIGH
HPE IMC PLAT <7.3 - RCE
CVSS 8.8
Details
Vulnerabilities 180