← back
CVE-2020-11975observed exploitation

CVE-2020-11975

65Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 30%
from disclosure to weapon172 days
Published on NVDJun 5
1st PoC+172d
VulnCheck+311d
exploitation probability
30%top 2% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
Affected products
n/a · Apache Unomi
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.