Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r6fv-qmrc-3h24

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

EPSS

Процентиль: 100%
0.93788
Критический

8.8 High

CVSS3

Дефекты

CWE-20
CWE-917

Связанные уязвимости

redhat
больше 15 лет назад

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

CVSS3: 8.8
nvd
больше 15 лет назад

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.

CVSS3: 8.8
debian
больше 15 лет назад

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Pl ...

CVSS3: 5.6
fstec
больше 15 лет назад

Уязвимость каркаса для разработки web приложений JBoss Seam платформы JBoss Enterprise Application Platform, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 100%
0.93788
Критический

8.8 High

CVSS3

Дефекты

CWE-20
CWE-917