CVE-2010-1871highunder attackCWE-917

CVE-2010-1871

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 8.8epss 83%
from disclosure to weapon1706 days
Published on NVDAug 4
1st PoC+1706d
metasploitJul 19
CISA KEV+4146d
exploitation probability
83%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
3 products (9 components)
Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 4 AS · Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 4 ES · Red Hat JBoss Enterprise Application Platform 4.3.0 for RHEL 5 Server
Action required by CISAfederal deadline: 2022-06-10

Apply updates per vendor instructions.

In short

JBoss Seam 2 doesn't properly filter user input in URLs, allowing attackers to inject malicious code that gets executed on the server. This bypasses security protections and can compromise the entire application.

Technical detail

CWE-917 (Expression Language Injection) in JBoss Seam 2 permits remote code execution through unsanitized URL parameters processed by JBoss EL. Attack requires improper Java Security Manager configuration; successful exploitation grants arbitrary code execution on the application server.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.