An improper neutralization of inputs used in expression language allows remote code execution with the highest privileges on the server.
Field Service Information FSI 14-25 “OnlineSuite AP3.0 - Security Fix” provides a patch to these issues.