'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2010-1871: JBoss Remote code execution
Severity:high
CVE ID:CVE-2010-1871
| Descripiton:
|
JBoss Seam is a Java EE5 framework that combines JSF and EJB3.0 components to provide a state-of-the-art model for developing Web-based enterprise applications. An input filtering vulnerability exists in the way that JBoss Seam handles certain parameterized JBoss EL expressions. If a remote attacker were able to trick an authenticated JBoss Seam user into visiting a specially crafted web page, it could lead to arbitrary code execution. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.