CVE-2020-13936
Last modified
CVE-2020-13936 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.. EPSS estimates a 22.71% chance of exploitation in the next 30 days.
Description
An attacker that is able to modify Velocity templates may execute arbitrary Java code or run arbitrary system commands with the same privileges as the account running the Servlet container. This applies to applications that allow untrusted users to upload/modify velocity templates running Apache Velocity Engine versions up to 2.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Velocity Engine | < 2.3 |
| Apache | Wss4j | 2.3.1 |
| Debian | Debian Linux | 9.0 |
| Oracle | Banking Deposits And Lines Of Credit Servicing | 2.12.0 |
| Oracle | Banking Enterprise Default Management | >= 2.3.0, <= 2.4.1 |
| Oracle | Banking Enterprise Default Management | 2.6.2 |
| Oracle | Banking Enterprise Default Management | 2.7.1 |
| Oracle | Banking Enterprise Default Management | 2.10.0 |
| Oracle | Banking Enterprise Default Management | 2.12.0 |
| Oracle | Banking Loans Servicing | 2.12.0 |
| Oracle | Banking Party Management | 2.7.0 |
| Oracle | Banking Platform | >= 2.3.0, <= 2.4.1 |
| Oracle | Banking Platform | 2.6.2 |
| Oracle | Banking Platform | 2.7.1 |
| Oracle | Communications Cloud Native Core Policy | 1.14.0 |
| Oracle | Communications Network Integrity | 7.3.6 |
| Oracle | Hospitality Token Proxy Service | 19.2 |
| Oracle | Retail Integration Bus | 19.0.1 |
| Oracle | Retail Order Broker | 16.0 |
| Oracle | Retail Service Backbone | 19.0.1 |
| Oracle | Retail Xstore Office Cloud Service | 16.0.6 |
| Oracle | Retail Xstore Office Cloud Service | 17.0.4 |
| Oracle | Retail Xstore Office Cloud Service | 18.0.3 |
| Oracle | Retail Xstore Office Cloud Service | 19.0.2 |
| Oracle | Retail Xstore Office Cloud Service | 20.0.1 |
| Oracle | Utilities Testing Accelerator | 6.0.0.1.1 |
| Oracle | Utilities Testing Accelerator | 6.0.0.2.2 |
| Oracle | Utilities Testing Accelerator | 6.0.0.3.1 |
References
- http://www.openwall.com/lists/oss-security/2021/03/10/1Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00019.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-52Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/03/10/1Mailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/03/msg00019.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202107-52Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-13936?
How severe is CVE-2020-13936?
How do I fix CVE-2020-13936?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-1393An elevation of privilege vulnerability exists when the Wind…7.8
- CVE-2020-13931If Apache TomEE 8.0.0-M1 - 8.0.3, 7.1.0 - 7.1.3, 7.0.0-M1 - …9.8
- CVE-2020-13932In Apache ActiveMQ Artemis 2.5.0 to 2.13.0, a specially craf…6.1
- CVE-2020-13933Apache Shiro before 1.6.0, when using Apache Shiro, a specia…7.5
- CVE-2020-13934An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.…7.5
- CVE-2020-13935The payload length in a WebSocket frame was not correctly va…7.5
- CVE-2020-13937Apache Kylin 2.0.0, 2.1.0, 2.2.0, 2.3.0, 2.3.1, 2.3.2, 2.4.0…5.3
- CVE-2020-13938Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged loc…5.5
- CVE-2020-13939Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-1394An elevation of privilege vulnerability exists in the way th…7.8
- CVE-2020-13940In Apache NiFi 1.0.0 to 1.11.4, the notification service man…5.5
- CVE-2020-13941Reported in SOLR-14515 (private) and fixed in SOLR-14561 (pu…8.8
Are you affected by CVE-2020-13936?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
