Loading
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
Use CWE-94, Apache vendor hub and Roller product page to widen CVE-2015-0249 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-17198, CVE-2014-0030 and CVE-2021-33580 for nearby disclosures in the same product family.