← All CVEs

CVE-2010-1871

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-12-10Remediation due 2022-06-10

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

8.8
CVSS
83.4%
EPSS (exploit prob.)
100th
EPSS percentile
2010-08-05
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-917

Affected products

VendorProductAffected versions
redhatjboss_enterprise_application_platform4.3.0
redhatenterprise_linux4
redhatenterprise_linux5
netapponcommand_balanceall versions
netapponcommand_insightall versions
netapponcommand_unified_managerall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2010-1871