{
  "id": "CVE-2010-1871",
  "url": "https://spydr.io/cve/CVE-2010-1871",
  "published": "2010-08-05T13:23:09.477Z",
  "modified": "2026-06-16T23:19:29.840Z",
  "score": 8.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.83397,
  "epss_percentile": 0.99676,
  "exploited": true,
  "kev": {
    "added": "2021-12-10",
    "due": "2022-06-10",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2010-1871"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "redhat",
    "netapp"
  ],
  "products": [
    "redhat jboss enterprise application platform",
    "netapp oncommand balance",
    "netapp oncommand insight",
    "netapp oncommand unified manager"
  ],
  "cwes": [
    "CWE-917"
  ],
  "description": "JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 8.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/bugtraq/2013-05/0117.html",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.redhat.com/support/errata/RHSA-2010-0564.html",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.securityfocus.com/bid/41994",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.securitytracker.com/id?1024253",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.vupen.com/english/advisories/2010/1929",
      "tags": [
        "Broken Link",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=615956",
      "tags": [
        "Issue Tracking"
      ]
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/60794",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20161017-0001/",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-1871",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2010-1871",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
