On this page

CWE-917: Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

Weakness Summary

The product constructs all or part of an expression language (EL) statement in a framework such as a Java Server Page (JSP) using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended EL statement before it is executed.

  • Canonical source: MITRE CWE-917 (opens in a new tab)
  • Published Atomicorp CVE observations: 8
  • Distinct affected products in those observations: 6
  • Active Atomicorp rules associated with this weakness: 14

Atomicorp Research Context

Atomicorp has published CVE-specific research observations associated with this weakness category. Each linked CVE page states whether the tested request was detected or blocked and is the authoritative customer-facing finding.

The CVEs and rules shown here are selected published examples, not a complete list of Atomicorp protections. If a CWE, CVE, or rule is absent from this page, no conclusion should be drawn about whether Atomicorp protects against that weakness or attack method.

A CWE describes a class of software weakness. It does not identify one exploit request, and association with a CWE does not mean that every vulnerability or exploitation path in that category is detected or blocked.

Selected Published CVE Observations

CVEVulnerabilityProductAtomicorp findingObserved rules
CVE-2021-44228Apache Log4j2 Remote Code Injectionlog4jAttack Blocked by Atomicorp345115 , 345117 , 345118 , 393655
CVE-2022-22947Spring Cloud Gateway Code Injectionspring cloud gatewayAttack Blocked by Atomicorp344370 , 393655
CVE-2020-17530Apache Struts 2.0.0-2.5.25 - Remote Code ExecutionstrutsAttack Blocked by Atomicorp344360 , 347009
CVE-2021-31805Apache Struts2 S2-062 - Remote Code ExecutionstrutsAttack Blocked by Atomicorp330791 , 340152
CVE-2022-26134Confluence - Remote Code Executionconfluence data centerAttack Blocked by Atomicorp337209 , 337211 , 340087
CVE-2021-45046Apache Log4j2 - Remote Code Injectionlog4jAttack Blocked by Atomicorp345115 , 345117 , 345118 , 393655
CVE-2019-16469Adobe Experience Manager - Expression Language Injectionexperience managerAttack Blocked by Atomicorp393655
CVE-2019-9041ZZZCMS 1.6.1 - Remote Code ExecutionzzzphpAttack Blocked by Atomicorp360153 , 380026

Associated Atomicorp WAF Rules

RuleStatusBehavior
330791Activedisruptive (deny)
337209Activedisruptive (deny)
337211Activedisruptive (deny)
340087Activedisruptive (deny)
340152Activedisruptive (deny)
344360Activedisruptive (deny)
344370Activedisruptive (deny)
345115Activedisruptive (deny)
345117Activedisruptive (deny)
345118Activedisruptive (deny)
347009Activedisruptive (deny)
360153Activedisruptive (deny)
380026Activedisruptive (deny)
393655Activedisruptive (deny)