CVE-2007-6433 PUBLISHED CVSS 7.5 HIGH

The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and execute arbitrary EJBQL commands via the order parameter.

EPSS 2.43% · 85.0th percentile

Risk Scores

CVSS v2.0
7.5
EPSS Score
2.43%
85.0th percentile

Affected Products

VendorProductVersions
jbossseam0
n/an/an/a

Timeline

References

Open in Interactive Console →