VDB

CVE-2010-1871

CVE-2010-1871 PUBLISHED KEV CVSS 6.800000190734863 MEDIUM

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

EPSS 83.40% · 99.7th percentile

Risk Scores

CVSS 2.0
6.800000190734863
EPSS Score
83.40%
99.7th percentile

Affected Products

VendorProductVersions
netapponcommand_insight
n/an/an/a
netapponcommand_unified_manager
netapponcommand_balance
redhatjboss_enterprise_application_platform4.3.0

Timeline

  • Aug 4, 2010 CVE Published
  • Apr 4, 2015 PoC Published
  • May 29, 2018 PoC Published
  • Feb 6, 2019 PoC Published
  • Dec 10, 2021 CISA KEV Added
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›