CVE-2011-2196
published 2011-07-27CVE-2011-2196: jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise…
PriorityP336medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.59%
83.6th percentile
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1484.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_soa_platform | — | — |
| redhat | jboss_enterprise_web_platform | — | — |
| redhat | jboss_seam_2_framework | <= 2.2.2 | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
| redhat | jboss_seam_2_framework | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6m4p-jvxh-733r: jboss-seam
ghsa_unreviewed·2022-05-17·CVSS 6.8
CVE-2011-2196 [MEDIUM] GHSA-6m4p-jvxh-733r: jboss-seam
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1484.
Red Hat
JBoss Seam EL interpolation in exception handling
vendor_redhat·2011-07-18·CVSS 6.8
CVE-2011-2196 [MEDIUM] JBoss Seam EL interpolation in exception handling
JBoss Seam EL interpolation in exception handling
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1484.
No detection rules found.
No public exploits indexed.
http://www.redhat.com/support/errata/RHSA-2011-0945.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0946.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0947.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0948.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0949.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0951.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0952.htmlhttp://www.securityfocus.com/bid/48716https://bugzilla.redhat.com/show_bug.cgi?id=712283http://www.redhat.com/support/errata/RHSA-2011-0945.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0946.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0947.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0948.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0949.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0950.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0951.htmlhttp://www.redhat.com/support/errata/RHSA-2011-0952.htmlhttp://www.securityfocus.com/bid/48716https://bugzilla.redhat.com/show_bug.cgi?id=712283
2011-07-27
Published