CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

180 vulnerabilities with CWE-917
CVE-2019-5364 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5363 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5362 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5361 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5360 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5359 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5358 CRITICAL
HPE IMC <7.3 - RCE
CVSS 9.8
CVE-2019-5355 HIGH
HPE IMC <7.3 - DoS
CVSS 7.5
CVE-2019-5354 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5353 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5352 CRITICAL
HPE IMC <7.3 - RCE
CVSS 9.8
CVE-2019-5351 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5349 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5348 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5346 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5345 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5344 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5343 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-5342 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11948 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11943 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11942 HIGH
HPE IMC <7.3 - RCE
CVSS 8.8
CVE-2019-11628 HIGH
QlikView Server <11.20 SR19-12.30 SR2 - Auth Bypass
CVSS 8.2
CVE-2019-9041 HIGH
ZZZCMS zzzphp <V1.6.1 - RCE
CVSS 7.2
CVE-2019-5916 CRITICAL
POWER EGG <2.9 - RCE
CVSS 9.8
Details
Vulnerabilities 180