CVE-2010-1871
high · 8.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-12-10Remediation due 2022-06-10
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.
8.8
CVSS
83.4%
EPSS (exploit prob.)
100th
EPSS percentile
2010-08-05
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-917
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| redhat | jboss_enterprise_application_platform | 4.3.0 |
| redhat | enterprise_linux | 4 |
| redhat | enterprise_linux | 5 |
| netapp | oncommand_balance | all versions |
| netapp | oncommand_insight | all versions |
| netapp | oncommand_unified_manager | all versions |
Check a specific version with /api/v1/cve/match.
References
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0117.html
- http://www.redhat.com/support/errata/RHSA-2010-0564.html
- http://www.securityfocus.com/bid/41994
- http://www.securitytracker.com/id?1024253
- http://www.vupen.com/english/advisories/2010/1929
- https://bugzilla.redhat.com/show_bug.cgi?id=615956
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60794
- https://security.netapp.com/advisory/ntap-20161017-0001/
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0117.html
- http://www.redhat.com/support/errata/RHSA-2010-0564.html
- http://www.securityfocus.com/bid/41994
- http://www.securitytracker.com/id?1024253
- http://www.vupen.com/english/advisories/2010/1929
- https://bugzilla.redhat.com/show_bug.cgi?id=615956
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60794
- https://security.netapp.com/advisory/ntap-20161017-0001/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-1871
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2010-1871