← Back

CVE-2011-1484

nvd nist
Published: Jul 27, 2011Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application.

Affected (35)

3 products
Jboss Enterprise Soa Platform
Jboss Seam 2 Framework
Configuration A
35 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 4.3.0 cp09
Version 5.1.0
Redhat
Version 4.3.0 cp04
Version 5.1.0
Redhat
Up to 2.2.2
Version 2.0.0 beta1
Version 2.0.0 cr1
Version 2.0.0 cr2
Version 2.0.0 cr3
Version 2.0.0 ga
Version 2.0.1 cr1
Version 2.0.1 cr2
Version 2.0.1 ga
Version 2.0.2 cr1
Version 2.0.2 cr2
Version 2.0.2 ga
Version 2.0.2 sp1
Version 2.0.3 cr1
Version 2.1.0 alpha1
Version 2.1.0 beta1
Version 2.1.0 cr1
Version 2.1.0 ga
Version 2.1.0 sp1
Version 2.1.1 cr1
Version 2.1.1 cr2
Version 2.1.1 ga
Version 2.1.2
Version 2.1.2 cr1
Version 2.1.2 cr2
Version 2.2.0 cr1
Version 2.2.0 ga
Version 2.2.1
Version 2.2.1 cr1
Version 2.2.1 cr2
Version 2.2.1 cr3

Related CWEs

References (16)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.