CVE-2020-17530Active Exploitation(apache / business_intelligence)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for apache business_intelligence systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected software : Apache Struts 2.0.0 - Struts 2.5.25.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-917

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • business_intelligence
  • communications_diameter_intelligence_hub
  • communications_policy_management
  • communications_pricing_design_center

Threat summary

  • Active exploitation appears in 1 classified signals
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Products
business_intelligencecommunications_diameter_intelligence_hubcommunications_policy_managementcommunications_pricing_design_centerfinancial_services_data_integration_hubhospitality_opera_5mysql_enterprise_monitorstruts

12 versions affected across 8 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-19: 1Active Exploitation · 2026-04-19: 1Technical Details · 2026-04-19: 104-19
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [HIGH] Active exploitation detected: CVE-2020-17530 Exploit in the wild confirmed for CVE-2020-17530 (CVSS null). Forced Object-Graph Navigation Language (OGNL) evaluation in Apache Struts, when evaluat... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post confirms that CVE-2020-17530 is being actively exploited in the wild via OGNL evaluation in Apache Struts, but no PoC, tool, patch, or workaround is provided.

    0000099
    5.6K followersView on X
CPE platform detail13 entries

13 of 13 entries

PartVendorProductVersionTarget SWTarget HW
Appapachestruts---
Apporaclebusiness_intelligence12.2.1.3.0--
Apporaclebusiness_intelligence12.2.1.4.0--
Apporaclecommunications_diameter_intelligence_hub8.0.0--
Apporaclecommunications_diameter_intelligence_hub8.1.0--
Apporaclecommunications_diameter_intelligence_hub8.2.0--
Apporaclecommunications_diameter_intelligence_hub8.2.3--
Apporaclecommunications_policy_management12.5.0--
Apporaclecommunications_pricing_design_center12.0.0.3.0--
Apporaclefinancial_services_data_integration_hub8.0.3--
Apporaclefinancial_services_data_integration_hub8.0.6--
Apporaclehospitality_opera_55.6--
Apporaclemysql_enterprise_monitor8.0.23--

Explore more