jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2011-07-27T01:00:00
Updated: 2024-08-06T22:28:41.792Z
Reserved: 2011-03-21T00:00:00
Link: CVE-2011-1484
Vulnrichment
No data.
NVD
Status : Modified
Published: 2011-07-27T02:42:27.203
Modified: 2011-10-26T02:58:19.950
Link: CVE-2011-1484
Redhat