Back

HIGH KEV

Seam2: Improper sanitization of parametrized JBoss EL expressions (ACE)

Published Aug 4, 2010 ·Due Jun 10, 2022

Description

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 4, 2010
Updated Oct 22, 2025
Reserved May 10, 2010
CISA Vulnrichment
Updated Feb 10, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Jul 27, 2010