CVE-2020-17530 | Oracle Communications Policy Management 12.5.0 Apache Struts2 expression language injection
A vulnerability classified as very critical has been found in Oracle Communications Policy Management 12.5.0. Affected is an unknown function of the component Apache Struts2. The manipulation leads to improper neutralization of special elements used in an expression language statement.
This vulnerability is traded as CVE-2020-17530. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.