Junglewise Threat Intelligence

CVE-2010-1871: Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability

CVE-2010-1871 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-12-10

Vendors: Red Hat.

Executive brief

JBoss Seam 2 fails to properly sanitize inputs for JBoss Expression Language (EL) expressions, allowing remote attackers to execute arbitrary code via a crafted URL. This vulnerability is specifically exploitable when the Java Security Manager is not properly configured.

Affected products

  • Red Hat JBoss Seam 2 (jboss-seam2) 2.x
  • Red Hat JBoss Enterprise Application Platform 4.3.0

Timeline

  • 2010-07-26: advisory: Original Red Hat Security Advisory (RHSA-2010-0564) date based on CVE year and vendor links
  • 2021-12-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-12-10: disclosed: NVD publication date