First published: Tue Mar 09 2021(Updated: )
Apache Velocity could allow a remote attacker to execute arbitrary code on the system, caused by a sandbox bypass flaw. By modifying the Velocity templates, an attacker could exploit this vulnerability to execute arbitrary code with the same privileges as the account running the Servlet container.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/velocity | <1.7-5ubuntu0.18.04.1~ | 1.7-5ubuntu0.18.04.1~ |
ubuntu/velocity | <1.7-5+ | 1.7-5+ |
ubuntu/velocity | <1.7-4ubuntu0.1~ | 1.7-4ubuntu0.1~ |
debian/velocity | 1.7-5+deb10u1 1.7-6 | |
redhat/eap7-artemis-wildfly-integration | <0:1.0.4-1.redhat_00001.1.el6ea | 0:1.0.4-1.redhat_00001.1.el6ea |
redhat/eap7-bouncycastle | <0:1.68.0-2.redhat_00005.1.el6ea | 0:1.68.0-2.redhat_00005.1.el6ea |
redhat/eap7-hal-console | <0:3.2.14-1.Final_redhat_00001.1.el6ea | 0:3.2.14-1.Final_redhat_00001.1.el6ea |
redhat/eap7-infinispan | <0:9.4.22-3.Final_redhat_00001.1.el6ea | 0:9.4.22-3.Final_redhat_00001.1.el6ea |
redhat/eap7-ironjacamar | <0:1.4.30-1.Final_redhat_00001.1.el6ea | 0:1.4.30-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-genericjms | <0:2.0.9-1.Final_redhat_00001.1.el6ea | 0:2.0.9-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-marshalling | <0:2.0.11-1.Final_redhat_00001.1.el6ea | 0:2.0.11-1.Final_redhat_00001.1.el6ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-6.Final_redhat_00007.1.el6ea | 0:1.7.2-6.Final_redhat_00007.1.el6ea |
redhat/eap7-jboss-weld | <3.1-api-0:3.1.0-6.SP3_redhat_00001.1.el6ea | 3.1-api-0:3.1.0-6.SP3_redhat_00001.1.el6ea |
redhat/eap7-jgroups-kubernetes | <0:1.0.16-1.Final_redhat_00001.1.el6ea | 0:1.0.16-1.Final_redhat_00001.1.el6ea |
redhat/eap7-netty | <0:4.1.60-1.Final_redhat_00001.1.el6ea | 0:4.1.60-1.Final_redhat_00001.1.el6ea |
redhat/eap7-resteasy | <0:3.11.4-1.Final_redhat_00001.1.el6ea | 0:3.11.4-1.Final_redhat_00001.1.el6ea |
redhat/eap7-undertow | <0:2.0.35-1.SP1_redhat_00001.1.el6ea | 0:2.0.35-1.SP1_redhat_00001.1.el6ea |
redhat/eap7-velocity | <0:2.3.0-1.redhat_00001.1.el6ea | 0:2.3.0-1.redhat_00001.1.el6ea |
redhat/eap7-weld-core | <0:3.1.6-1.Final_redhat_00001.1.el6ea | 0:3.1.6-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly | <0:7.3.7-1.GA_redhat_00002.1.el6ea | 0:7.3.7-1.GA_redhat_00002.1.el6ea |
redhat/eap7-wildfly-elytron | <0:1.10.12-1.Final_redhat_00001.1.el6ea | 0:1.10.12-1.Final_redhat_00001.1.el6ea |
redhat/eap7-wildfly-http-client | <0:1.0.26-1.Final_redhat_00001.1.el6ea | 0:1.0.26-1.Final_redhat_00001.1.el6ea |
redhat/eap7-xalan-j2 | <0:2.7.1-36.redhat_00013.1.el6ea | 0:2.7.1-36.redhat_00013.1.el6ea |
redhat/eap7-yasson | <0:1.0.9-1.redhat_00001.1.el6ea | 0:1.0.9-1.redhat_00001.1.el6ea |
redhat/eap7-artemis-wildfly-integration | <0:1.0.4-1.redhat_00001.1.el7ea | 0:1.0.4-1.redhat_00001.1.el7ea |
redhat/eap7-bouncycastle | <0:1.68.0-2.redhat_00005.1.el7ea | 0:1.68.0-2.redhat_00005.1.el7ea |
redhat/eap7-hal-console | <0:3.2.14-1.Final_redhat_00001.1.el7ea | 0:3.2.14-1.Final_redhat_00001.1.el7ea |
redhat/eap7-infinispan | <0:9.4.22-3.Final_redhat_00001.1.el7ea | 0:9.4.22-3.Final_redhat_00001.1.el7ea |
redhat/eap7-ironjacamar | <0:1.4.30-1.Final_redhat_00001.1.el7ea | 0:1.4.30-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-genericjms | <0:2.0.9-1.Final_redhat_00001.1.el7ea | 0:2.0.9-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-marshalling | <0:2.0.11-1.Final_redhat_00001.1.el7ea | 0:2.0.11-1.Final_redhat_00001.1.el7ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-6.Final_redhat_00007.1.el7ea | 0:1.7.2-6.Final_redhat_00007.1.el7ea |
redhat/eap7-jboss-weld | <3.1-api-0:3.1.0-6.SP3_redhat_00001.1.el7ea | 3.1-api-0:3.1.0-6.SP3_redhat_00001.1.el7ea |
redhat/eap7-jgroups-kubernetes | <0:1.0.16-1.Final_redhat_00001.1.el7ea | 0:1.0.16-1.Final_redhat_00001.1.el7ea |
redhat/eap7-netty | <0:4.1.60-1.Final_redhat_00001.1.el7ea | 0:4.1.60-1.Final_redhat_00001.1.el7ea |
redhat/eap7-resteasy | <0:3.11.4-1.Final_redhat_00001.1.el7ea | 0:3.11.4-1.Final_redhat_00001.1.el7ea |
redhat/eap7-undertow | <0:2.0.35-1.SP1_redhat_00001.1.el7ea | 0:2.0.35-1.SP1_redhat_00001.1.el7ea |
redhat/eap7-velocity | <0:2.3.0-1.redhat_00001.1.el7ea | 0:2.3.0-1.redhat_00001.1.el7ea |
redhat/eap7-weld-core | <0:3.1.6-1.Final_redhat_00001.1.el7ea | 0:3.1.6-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly | <0:7.3.7-1.GA_redhat_00002.1.el7ea | 0:7.3.7-1.GA_redhat_00002.1.el7ea |
redhat/eap7-wildfly-elytron | <0:1.10.12-1.Final_redhat_00001.1.el7ea | 0:1.10.12-1.Final_redhat_00001.1.el7ea |
redhat/eap7-wildfly-http-client | <0:1.0.26-1.Final_redhat_00001.1.el7ea | 0:1.0.26-1.Final_redhat_00001.1.el7ea |
redhat/eap7-xalan-j2 | <0:2.7.1-36.redhat_00013.1.el7ea | 0:2.7.1-36.redhat_00013.1.el7ea |
redhat/eap7-yasson | <0:1.0.9-1.redhat_00001.1.el7ea | 0:1.0.9-1.redhat_00001.1.el7ea |
redhat/eap7-artemis-wildfly-integration | <0:1.0.4-1.redhat_00001.1.el8ea | 0:1.0.4-1.redhat_00001.1.el8ea |
redhat/eap7-bouncycastle | <0:1.68.0-2.redhat_00005.1.el8ea | 0:1.68.0-2.redhat_00005.1.el8ea |
redhat/eap7-hal-console | <0:3.2.14-1.Final_redhat_00001.1.el8ea | 0:3.2.14-1.Final_redhat_00001.1.el8ea |
redhat/eap7-infinispan | <0:9.4.22-3.Final_redhat_00001.1.el8ea | 0:9.4.22-3.Final_redhat_00001.1.el8ea |
redhat/eap7-ironjacamar | <0:1.4.30-1.Final_redhat_00001.1.el8ea | 0:1.4.30-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-genericjms | <0:2.0.9-1.Final_redhat_00001.1.el8ea | 0:2.0.9-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-marshalling | <0:2.0.11-1.Final_redhat_00001.1.el8ea | 0:2.0.11-1.Final_redhat_00001.1.el8ea |
redhat/eap7-jboss-server-migration | <0:1.7.2-6.Final_redhat_00007.1.el8ea | 0:1.7.2-6.Final_redhat_00007.1.el8ea |
redhat/eap7-jboss-weld | <3.1-api-0:3.1.0-6.SP3_redhat_00001.1.el8ea | 3.1-api-0:3.1.0-6.SP3_redhat_00001.1.el8ea |
redhat/eap7-jgroups-kubernetes | <0:1.0.16-1.Final_redhat_00001.1.el8ea | 0:1.0.16-1.Final_redhat_00001.1.el8ea |
redhat/eap7-netty | <0:4.1.60-1.Final_redhat_00001.1.el8ea | 0:4.1.60-1.Final_redhat_00001.1.el8ea |
redhat/eap7-resteasy | <0:3.11.4-1.Final_redhat_00001.1.el8ea | 0:3.11.4-1.Final_redhat_00001.1.el8ea |
redhat/eap7-undertow | <0:2.0.35-1.SP1_redhat_00001.1.el8ea | 0:2.0.35-1.SP1_redhat_00001.1.el8ea |
redhat/eap7-velocity | <0:2.3.0-1.redhat_00001.1.el8ea | 0:2.3.0-1.redhat_00001.1.el8ea |
redhat/eap7-weld-core | <0:3.1.6-1.Final_redhat_00001.1.el8ea | 0:3.1.6-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly | <0:7.3.7-1.GA_redhat_00002.1.el8ea | 0:7.3.7-1.GA_redhat_00002.1.el8ea |
redhat/eap7-wildfly-elytron | <0:1.10.12-1.Final_redhat_00001.1.el8ea | 0:1.10.12-1.Final_redhat_00001.1.el8ea |
redhat/eap7-wildfly-http-client | <0:1.0.26-1.Final_redhat_00001.1.el8ea | 0:1.0.26-1.Final_redhat_00001.1.el8ea |
redhat/eap7-xalan-j2 | <0:2.7.1-36.redhat_00013.1.el8ea | 0:2.7.1-36.redhat_00013.1.el8ea |
redhat/eap7-yasson | <0:1.0.9-1.redhat_00001.1.el8ea | 0:1.0.9-1.redhat_00001.1.el8ea |
IBM Sterling External Authentication Server | <=6.0.3 | |
IBM Sterling External Authentication Server | <=6.1.0 | |
redhat/velocity | <2.3 | 2.3 |
Apache Velocity Engine | <2.3 | |
Apache WSS4J | =2.3.1 | |
Debian Debian Linux | =9.0 | |
Oracle Banking Deposits And Lines Of Credit Servicing | =2.12.0 | |
Oracle Banking Enterprise Default Management | >=2.3.0<=2.4.1 | |
Oracle Banking Enterprise Default Management | =2.6.2 | |
Oracle Banking Enterprise Default Management | =2.7.1 | |
Oracle Banking Enterprise Default Management | =2.10.0 | |
Oracle Banking Enterprise Default Management | =2.12.0 | |
Oracle Banking Loans Servicing | =2.12.0 | |
Oracle Banking Party Management | =2.7.0 | |
Oracle Banking Platform | >=2.3.0<=2.4.1 | |
Oracle Banking Platform | =2.6.2 | |
Oracle Banking Platform | =2.7.1 | |
Oracle Communications Cloud Native Core Policy | =1.14.0 | |
Oracle Communications Network Integrity | =7.3.6 | |
Oracle Hospitality Token Proxy Service | =19.2 | |
Oracle Retail Integration Bus | =19.0.1 | |
Oracle Retail Order Broker | =16.0 | |
Oracle Retail Service Backbone | =19.0.1 | |
Oracle Retail Xstore Office Cloud Service | =16.0.6 | |
Oracle Retail Xstore Office Cloud Service | =17.0.4 | |
Oracle Retail Xstore Office Cloud Service | =18.0.3 | |
Oracle Retail Xstore Office Cloud Service | =19.0.2 | |
Oracle Retail Xstore Office Cloud Service | =20.0.1 | |
Oracle Utilities Testing Accelerator | =6.0.0.1.1 | |
Oracle Utilities Testing Accelerator | =6.0.0.2.2 | |
Oracle Utilities Testing Accelerator | =6.0.0.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)