← Back

CVE-2011-2196

nvd nist
Published: Jul 27, 2011Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1484.

Affected (37)

4 products
Jboss Enterprise Soa Platform
Jboss Enterprise Web Platform
Jboss Seam 2 Framework
Configuration A
37 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 4.3.0
Version 4.3.0 cp09
Version 5.1.1
Redhat
Version 4.3.0 cp05
Version 5.1.0
Version 5.1.1
Redhat
Up to 2.2.2
Version 2.0.0 beta1
Version 2.0.0 cr1
Version 2.0.0 cr2
Version 2.0.0 cr3
Version 2.0.0 ga
Version 2.0.1 cr1
Version 2.0.1 cr2
Version 2.0.1 ga
Version 2.0.2 cr1
Version 2.0.2 cr2
Version 2.0.2 ga
Version 2.0.2 sp1
Version 2.0.3 cr1
Version 2.1.0 alpha1
Version 2.1.0 beta1
Version 2.1.0 cr1
Version 2.1.0 ga
Version 2.1.0 sp1
Version 2.1.1 cr1
Version 2.1.1 cr2
Version 2.1.1 ga
Version 2.1.2
Version 2.1.2 cr1
Version 2.1.2 cr2
Version 2.2.0 cr1
Version 2.2.0 ga
Version 2.2.1
Version 2.2.1 cr1
Version 2.2.1 cr2
Version 2.2.1 cr3

Related CWEs

References (20)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.