CVE-2020-11975 - MergeBase Vulnerability Database
Risk Score
High severity
Out of 10
Jun 5, 2020
Jul 21, 2021


Apache Unomi allows conditions to use OGNL scripting which offers the possibility to call static Java classes from the JDK that could execute code with the permission level of the running Java process.
MergeBase Comment
Apache Unomi up to version 1.5.0 is vulnerable to a remote code execution exploit through OGNL. Through a crafted payload you are able to invoke the Runtime.Exec JDK function. Exec is able to run commands with the same permissions as the running Java user.
Common Weakness Enumeration (CWE)

Discover More from MergeBase

Open Source Protection

Stay on top of the real risk of open source at any time.

Avoid false positives and get sophisticated upgrade guidance based on risk, compatibility and popularity.

More on Continuous Protection

Add RunTime Protection

Detect and defend against known-vulnerabilities at runtime. The only SCA to do so.

The quickest way to respond to an imminent threat like log4j with CVE-2021-44228.

More on Run-time Protection

Shift Left Now

CodeGreen is an early-warning defence for your in-house development and integrates directly into GitHub and BitBucket

More on BitBucket and Github apps