CVE-2010-1871

redhat jboss enterprise application platform, netapp oncommand balance, netapp oncommand insight

Published 5 Aug 2010 · updated 16 Jun 2026 · Analyzed

8.8 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 10 Dec 2021, with a remediation deadline of 10 Jun 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

References