CVE-2010-1871
Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 83.40% probability · 100th percentile
- CISA KEV
- Listed 10 December 2021 · due 10 June 2022
- Weakness
- CWE-917
- Affected
- redhat/jboss enterprise application platform · netapp/oncommand balance · netapp/oncommand insight · netapp/oncommand unified manager
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-1871
References
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0117.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0564.htmlBroken Link
- http://www.securityfocus.com/bid/41994Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024253Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/1929Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=615956Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60794Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20161017-0001/Third Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0117.htmlBroken Link
- http://www.redhat.com/support/errata/RHSA-2010-0564.htmlBroken Link
- http://www.securityfocus.com/bid/41994Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024253Broken Link, Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2010/1929Broken Link, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=615956Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60794Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20161017-0001/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-1871US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.