CVE Database
/

CVE-2011-1484

Back to search

CVE-2011-1484

Published: Jul 27, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2011:1251
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0462
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0463
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0461
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0460
vendor-advisory
x_refsource_REDHAT
RHSA-2011:1148
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now