Affected Versions:
JBoss Seam 2.0.2 SP1JBoss Seam 2.0.2jbosseam 2.0
Vulnerability description:
JBoss Seam is a Java EE5 framework that combines JSF and EJB3.0 components,
This provides a new mode for developing Web-based enterprise applications. JBoss Seam has the input filter vulnerability when processing some parameterized JBoss EL expressions.
If a remote attacker can trick authenticated JBoss Seam users into accessing a specially crafted webpage, arbitrary code may be executed.
<* Reference
Jan Lieskovsky (
Jlieskov@redhat.com)
Https://bugzilla.redhat.com/show_bug.cgi? Format = multiple & amp; id = 615956
Https://www.redhat.com/support/errata/RHSA-2010-0564.html
*>
Vendor patch: RedHat ------ RedHat has released a security Bulletin (RHSA-2010: 0564-01) and patch: RHSA-2010: 0564-01: Important: jboss-seam2 security update link: https://www.redhat.com/support/errata/RHSA-2010-0564.html