Executive brief
JBoss Seam 2 fails to properly sanitize inputs for JBoss Expression Language (EL) expressions, allowing remote attackers to execute arbitrary code via a crafted URL. This vulnerability is specifically exploitable when the Java Security Manager is not properly configured.
Affected products
- Red Hat JBoss Seam 2 (jboss-seam2) 2.x
- Red Hat JBoss Enterprise Application Platform 4.3.0
Timeline
- 2010-07-26: advisory: Original Red Hat Security Advisory (RHSA-2010-0564) date based on CVE year and vendor links
- 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-12-10: disclosed: NVD publication date