Expression Language Server Side Template Injection (CVE-2020-9296)

Related Vulnerabilities: CVE-2020-9296  

Check Point Reference: CPAI-2024-0119 Date Published: 10 Apr 2024 Severity: Critical Last Updated: Wednesday 10 April, 2024 Source: Industry Reference:CVE-2020-9296
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Vulnerability Description A remote attacker can inject a malicious commands into a template engine. Successful exploitation could result in the execution of arbitrary code in the affected web server.