CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.
180 vulnerabilities with CWE-917
CVE-2019-5364
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5363
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5362
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5361
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5360
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5359
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5358
CRITICAL
HPE IMC <7.3 - RCE
CVSS 9.8
CVE-2019-5355
HIGH
HPE IMC <7.3 - DoS
CVSS 7.5
CVE-2019-5354
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5353
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5352
CRITICAL
HPE IMC <7.3 - RCE
CVSS 9.8
CVE-2019-5351
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5349
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5348
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5346
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5345
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5344
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5343
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5342
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11948
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11943
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11942
HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11628
HIGH
QlikView Server <11.20 SR19-12.30 SR2 - Auth Bypass
CVSS 8.2
CVE-2019-9041
HIGH
ZZZCMS zzzphp <V1.6.1 - RCE
CVSS 7.2
CVE-2019-5916
CRITICAL
POWER EGG <2.9 - RCE
CVSS 9.8
Details
Vulnerabilities
180