Code Injection in Apache Velocity Engine - CVE-2020-13936

 

Code Injection in Apache Velocity Engine - CVE-2020-13936

Published: March 16, 2021


Vulnerability identifier: #VU51511
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2020-13936
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
Apache Velocity Engine
IBM App Connect Enterprise
Oracle GoldenGate Studio
Jazz Foundation
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
Gentoo Linux
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Linux Enterprise Module for SUSE Manager Server
SUSE Enterprise Storage
SUSE Linux Enterprise Module for Development Tools
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
Fedora
Oracle Communications Cloud Native Core Policy
IBM Cloud Pak System
Oracle Banking Enterprise Default Management
Oracle Banking Party Management
Oracle Banking Deposits and Lines of Credit Servicing
Oracle Banking Loans Servicing
IBM Intelligent Operations Center
Oracle Communications Network Integrity
IBM Integration Bus
Oracle Identity Management Suite
Middleware Common Libraries and Tools
Oracle Middleware Common Libraries and Tools
Oracle Hospitality Token Proxy Service
Oracle Banking APIs
QRadar User Behavior Analytics
IBM Match 360
IBM Sterling External Authentication Server
IBM UrbanCode Release
Oracle Banking Platform
Oracle Communications User Data Repository
Oracle Retail Order Broker
Oracle Retail Service Backbone
Oracle Banking Digital Experience
IBM Planning Analytics Workspace
Cloud Pak for Network Automation
UrbanCode Build
Engineering Lifecycle Management - Jazz Foundation
Engineering Test Management
Storage Protect for Virtual Environments: Data Protection for Hyper-V
Storage Protect for Virtual Environments: Data Protection for VMware
Oracle Utilities Application Framework
Oracle Utilities Testing Accelerator
Oracle Retail Xstore Office Cloud Service
JBoss Enterprise Application Platform
Oracle WebLogic Server
Juniper Secure Analytics (JSA)
Oracle Retail Integration Bus
velocity (Ubuntu package)
plexus-build-api
sisu
sisu-mojos
java_cup
maven-artifact-transfer
atinject
plexus-languages
munge-maven-plugin
plexus-resources
apiguardian
jdom
maven-shared-incremental
opentest4j
apache-commons-logging
jakarta-annotations
eap7-jettison (Red Hat package)
apache-commons-jxpath
apache-commons-cli
plexus-sec-dispatcher
maven-resolver
eap7-velocity (Red Hat package)
maven-remote-resources-plugin
jflex
velocity
plexus-cipher
velocity-help
slf4j
xz-java
apache-commons-beanutils
byte-buddy
maven-dependency-analyzer
modello
felix-utils
fusesource-pom
jsoup
maven-dependency-analyzer-javadoc
apache-commons-codec
apache-commons-compress
plexus-interpolation
snakeyaml
eap7-snakeyaml (Red Hat package)
beust-jcommander
qdox
maven-doxia-sitetools
maven-doxia-sitetools-javadoc
maven-doxia-module-xdoc
maven-doxia-javadoc
maven-doxia-sink-api
maven-doxia-module-xhtml5
maven-doxia-module-fml
maven-doxia-test-docs
maven-doxia-module-apt
maven-doxia-core
cdi-api
jdom2
plexus-containers
plexus-velocity
plexus-velocity-javadoc
jansi
hamcrest
velocity-engine-core-javadoc
velocity-engine-core
plexus-classworlds
apache-commons-io
xmlunit
plexus-compiler
eap7-jackson-databind (Red Hat package)
univocity-parsers
eap7-jackson-jaxrs-providers (Red Hat package)
eap7-jackson-core (Red Hat package)
eap7-jackson-modules-java8 (Red Hat package)
eap7-jackson-annotations (Red Hat package)
eap7-jackson-modules-base (Red Hat package)
maven-enforcer
maven-surefire
maven-antrun-plugin
maven-shared-io
maven-file-management
maven-dependency-tree
jsr-305
eap7-resteasy (Red Hat package)
maven-common-artifact-filters
maven-dependency-plugin
objenesis
eap7-apache-cxf (Red Hat package)
maven-filtering
maven-resources-plugin
maven-plugin-build-helper
plexus-io
maven-jar-plugin
maven-source-plugin
apache-commons-collections
eap7-hal-console (Red Hat package)
cglib
maven-assembly-plugin
plexus-utils
maven-plugin-testing
maven-invoker
maven-invoker-javadoc
maven-shared-utils
maven-wagon
maven-archiver
maven-surefire-provider-junit5
maven-surefire-provider-junit5-javadoc
maven-surefire-plugins-javadoc
maven-surefire-plugin
maven-failsafe-plugin
maven-surefire-report-plugin
maven-surefire-plugin-bootstrap
maven-surefire-report-plugin-bootstrap
maven-surefire-provider-testng
maven-surefire-provider-junit
maven-surefire-report-parser
maven-failsafe-plugin-bootstrap
maven-surefire-javadoc
maven-plugin-tools
maven
mockito
maven-compiler-plugin
maven-invoker-plugin-javadoc
maven-invoker-plugin
maven-dependency-plugin-javadoc
maven-javadoc-plugin-bootstrap
maven-javadoc-plugin-javadoc
maven-javadoc-plugin
apache-commons-lang3
maven-plugin-plugin-javadoc
maven-plugin-plugin
maven-plugin-plugin-bootstrap
maven-plugin-tools-java
maven-plugin-tools-api
maven-script-beanshell
maven-plugin-tools-javadoc
maven-script-ant
maven-plugin-annotations
maven-plugin-tools-annotations
maven-plugin-tools-ant
maven-plugin-tools-model
maven-plugin-tools-generators
maven-plugin-tools-beanshell
assertj-core
maven-reporting-api
maven-reporting-api-javadoc
maven-reporting-impl
maven-reporting-impl-javadoc
xmvn
eap7-netty (Red Hat package)
easymock
google-guice
plexus-archiver
httpcomponents-core
httpcomponents-client
junit
xbean
jakarta-servlet
maven-plugin-bundle
aqute-bnd
junit5
javapackages-tools
plexus-components-pom
osgi-compendium
eap7-wildfly (Red Hat package)
plexus-pom
testng
felix-parent
osgi-core
osgi-annotation
objectweb-asm
httpcomponents-project
apache-parent
guava
apache-resource-bundles
maven-parent
apache-commons-parent
mojo-parent
IBM Qradar SIEM

Detailed vulnerability description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to improper input validation. A remote attacker with ability to modify Velocity templates can inject and execute arbitrary Java code on the system with the same privileges as the account running the Servlet container.



How to mitigate CVE-2020-13936

Install updates from vendor's website.

Sources