GHSA-jc35-q369-45pv · Severity: critical · Ecosystem: maven — Remote code execution in Apache Struts
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.
Conclusion & alert: CVE-2020-17530 is rated Critical Active Threat (100/100): CVSS Critical severity, with high exploitation likelihood (EPSS 95.92%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2021-11-03) affecting Apache / Struts. a weakness (CWE-917) Unauthenticated remote administrative access may be possible. EPSS rose +1.55% over the last day, indicating growing attacker interest. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: Apache Struts Remote Code Execution Vulnerability · CISA KEV detail
: 2021-11-03
: 2022-05-03
: Apply updates per vendor instructions.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 94.38% | 95.92% | +1.55% |
| 2 | 2026-03-04 | 94.31% | 94.38% | +0.07% |
| 3 | 2026-03-01 | — | 94.31% | — |
Full EPSS history (26 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-jc35-q369-45pv · Severity: critical · Ecosystem: maven — Remote code execution in Apache Struts
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2020-17530 |
suse
|
high | CVE-2020-17530 severity important: SUSE including 1 source package names (struts), 2 product×package rows across 2 product lines (SUSE Manager Server Module 4.0, SUSE Manager Server Module 4.1): Known Not Affected 2. | https://www.suse.com/security/cve/CVE-2020-17530/ |
ubuntu
|
medium | CVE-2020-17530 medium priority: Ubuntu including 1 source packages (libstruts1.2-java), 6 status rows across 6 suites (bionic, focal, groovy, trusty, upstream, xenial): DNE 5, not-affected 1. | https://ubuntu.com/security/CVE-2020-17530 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | struts | >= 2.0.0, < 2.5.30 | cpe:2.3:a:apache:struts:*:*:*:*:*:*:*:* |
| oracle | business_intelligence | 12.2.1.3.0 | cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:* |
| oracle | business_intelligence | 12.2.1.4.0 | cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:* |
| oracle | communications_diameter_intelligence_hub | 8.0.0 | cpe:2.3:a:oracle:communications_diameter_intelligence_hub:8.0.0:*:*:*:*:*:*:* |
| oracle | communications_diameter_intelligence_hub | 8.1.0 | cpe:2.3:a:oracle:communications_diameter_intelligence_hub:8.1.0:*:*:*:*:*:*:* |
| oracle | communications_diameter_intelligence_hub | 8.2.0 | cpe:2.3:a:oracle:communications_diameter_intelligence_hub:8.2.0:*:*:*:*:*:*:* |
| oracle | communications_diameter_intelligence_hub | 8.2.3 | cpe:2.3:a:oracle:communications_diameter_intelligence_hub:8.2.3:*:*:*:*:*:*:* |
| oracle | communications_policy_management | 12.5.0 | cpe:2.3:a:oracle:communications_policy_management:12.5.0:*:*:*:*:*:*:* |
| oracle | communications_pricing_design_center | 12.0.0.3.0 | cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:* |
| oracle | financial_services_data_integration_hub | 8.0.3 | cpe:2.3:a:oracle:financial_services_data_integration_hub:8.0.3:*:*:*:*:*:*:* |
| oracle | financial_services_data_integration_hub | 8.0.6 | cpe:2.3:a:oracle:financial_services_data_integration_hub:8.0.6:*:*:*:*:*:*:* |
| oracle | hospitality_opera_5 | 5.6 | cpe:2.3:a:oracle:hospitality_opera_5:5.6:*:*:*:*:*:*:* |
| oracle | mysql_enterprise_monitor | 8.0.23 | cpe:2.3:a:oracle:mysql_enterprise_monitor:8.0.23:*:*:*:*:*:*:* |