Home
CRITICAL: 10.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HDefault status
unaffected
3.0 (custom)
affected
Description
An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.
Problem types
Product status
3.0 (custom)
Credits
Fabian Weber (CODE WHITE GmbH)
Dr. Florian Hauser (CODE WHITE GmbH)
References
www.bbraun.com/productsecurity