CVE-2010-1871 KEV EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 83.4% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-06-10.
Description
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 83.4% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-917 |
| On CISA KEV | yes — remediate by 2022-06-10 |
| Public exploit | yes |
| Published | 2010-08-05 |
| Last modified | 2026-06-16 |
CISA KEV
| Name | Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability |
|---|---|
| Added | 2021-12-10 |
| Due | 2022-06-10 |
| Vendor / product | Red Hat / JBoss Seam 2 |
| Ransomware use | none reported |
Affected (5)
| Vendor | Product |
|---|---|
| netapp | oncommand balance |
| netapp | oncommand insight |
| netapp | oncommand unified manager |
| redhat | enterprise linux |
| redhat | jboss enterprise application platform |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | JBoss Seam 2 - Arbitrary File Upload / Execution (Metasploit) | 2015-04-06 |
References
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0117.html
- http://www.redhat.com/support/errata/RHSA-2010-0564.html
- http://www.securityfocus.com/bid/41994
- http://www.securitytracker.com/id?1024253
- http://www.vupen.com/english/advisories/2010/1929
- https://bugzilla.redhat.com/show_bug.cgi?id=615956
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60794
- https://security.netapp.com/advisory/ntap-20161017-0001/
- http://archives.neohapsis.com/archives/bugtraq/2013-05/0117.html
- http://www.redhat.com/support/errata/RHSA-2010-0564.html
- http://www.securityfocus.com/bid/41994
- http://www.securitytracker.com/id?1024253
- http://www.vupen.com/english/advisories/2010/1929
- https://bugzilla.redhat.com/show_bug.cgi?id=615956
- https://exchange.xforce.ibmcloud.com/vulnerabilities/60794
- https://security.netapp.com/advisory/ntap-20161017-0001/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2010-1871
→ the Explorer · watch your stack · NVD