Home
MEDIUM: 4.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:NDefault status
unaffected
Any version before w29.032
affected
w30 (custom) before w30.044
affected
w31 (custom) before w31.040
affected
Description
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
Problem types
CWE-94 Improper Control of Generation of Code ('Code Injection')
Product status
Any version before w29.032
w30 (custom) before w30.044
w31 (custom) before w31.040
References
code-white.com/public-vulnerability-list/