CVE-2020-13936

HIGH

Apache Velocity Engine < 2.3 - Remote Code Execution via Template Modification

Title source: llm
STIX 2.1

Description

An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.

References (23)

Core 23
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/03/10/1
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2021/03/msg00019.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202107-52
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 8.8
EPSS 0.1640
EPSS Percentile 95.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (30)
apache/velocity_engine < 2.3
apache/wss4j 2.3.1
debian/debian_linux 9.0
oracle/banking_deposits_and_lines_of_credit_servicing 2.12.0
oracle/banking_enterprise_default_management 2.6.2
oracle/banking_enterprise_default_management 2.7.1
oracle/banking_enterprise_default_management 2.10.0
oracle/banking_enterprise_default_management 2.12.0
oracle/banking_enterprise_default_management 2.3.0 - 2.4.1
oracle/banking_loans_servicing 2.12.0
... and 20 more
Published Mar 10, 2021
Tracked Since Feb 18, 2026