CVE-2010-1871
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Apply updates per vendor instructions.
JBoss Seam 2 doesn't properly filter user input in URLs, allowing attackers to inject malicious code that gets executed on the server. This bypasses security protections and can compromise the entire application.
CWE-917 (Expression Language Injection) in JBoss Seam 2 permits remote code execution through unsanitized URL parameters processed by JBoss EL. Attack requires improper Java Security Manager configuration; successful exploitation grants arbitrary code execution on the application server.
The full analysis of this CVE is available in Portuguese →