CVE Database
/

CVE-2011-2196

Back to search

CVE-2011-2196

Published: Jul 27, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0; JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0, 4.3.0.CP09, and 5.1.1; and JBoss Enterprise Web Platform 5.1.1, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1484.

VendorProductVersions

n/a

n/a

affected
n/a

References

48716
vdb-entry
x_refsource_BID
RHSA-2011:0946
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0948
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0949
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0951
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0945
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0950
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0947
vendor-advisory
x_refsource_REDHAT
RHSA-2011:0952
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now