CVE-2010-1871
redhat jboss enterprise application platform, netapp oncommand balance, netapp oncommand insight
Published 5 Aug 2010 · updated 16 Jun 2026 · Analyzed
8.8 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Dec 2021, with a remediation deadline of 10 Jun 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.
References
- archives.neohapsis.com/archives/bugtraq/2013-05/0117.html · Broken Link
- www.redhat.com/support/errata/RHSA-2010-0564.html · Broken Link
- www.securityfocus.com/bid/41994 · Broken Link, Third Party Advisory, VDB Entry
- www.securitytracker.com/id?1024253 · Broken Link, Third Party Advisory, VDB Entry
- www.vupen.com/english/advisories/2010/1929 · Broken Link, Vendor Advisory
- bugzilla.redhat.com/show_bug.cgi?id=615956 · Issue Tracking
- exchange.xforce.ibmcloud.com/vulnerabilities/60794 · Third Party Advisory, VDB Entry
- security.netapp.com/advisory/ntap-20161017-0001/ · Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-1871 · US Government Resource