CVE-2011-1484
JBoss Seam privilege escalation caused by EL interpolation in FacesMessages
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
jboss-seam.jar in the JBoss Seam 2 framework 2.2.x and earlier, as distributed in Red Hat JBoss Enterprise SOA Platform 4.3.0.CP04 and 5.1.0 and JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.3.0.CP09 and 5.1.0, does not properly restrict use of Expression Language (EL) statements in FacesMessages during page exception handling, which allows remote attackers to execute arbitrary Java code via a crafted URL to an application.
jboss-seam.jar en el framework JBoss Seam 2 2.2.x y versiones anteriores, tal como se distribuye con la plataforma Hat JBoss Enterprise SOA 4.3.0.CP04 y 5.1.0 y JBoss Enterprise Application Platform (JBoss EAP o JBEAP) 4.3.0.CP09 y 5.1.0, no restringen el uso de instrucciones de "Expression Language" (EL) en FacesMessages durante el manejo de excepciones de página, lo que permite a atacantes remotos ejecutar código Java arbitrario a través de una URL modificada a una aplicación.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-03-21 CVE Reserved
- 2011-07-27 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://docs.redhat.com/docs/en-US/JBoss_Communications_Platform/5.1/html/5.1.1_Release_Notes/ar01s05.html | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 4.3.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "4.3.0" | cp09 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | 5.1.0 Search vendor "Redhat" for product "Jboss Enterprise Application Platform" and version "5.1.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Soa Platform Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" | 4.3.0 Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" and version "4.3.0" | cp04 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Soa Platform Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" | 5.1.0 Search vendor "Redhat" for product "Jboss Enterprise Soa Platform" and version "5.1.0" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | <= 2.2.2 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version " <= 2.2.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.0" | beta1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.0" | cr1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.0" | cr2 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.0" | cr3 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.0" | ga |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.1" | cr1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.1" | cr2 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.1" | ga |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.2 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.2" | cr1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.2 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.2" | cr2 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.2 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.2" | ga |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.2 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.2" | sp1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.0.3 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.0.3" | cr1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.0" | alpha1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.0" | beta1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.0" | cr1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.0" | ga |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.0" | sp1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.1" | cr1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.1" | cr2 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.1" | ga |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.2 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.2" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.2 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.2" | cr1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.1.2 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.1.2" | cr2 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.2.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.2.0" | cr1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.2.0 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.2.0" | ga |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.2.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.2.1" | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.2.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.2.1" | cr1 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.2.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.2.1" | cr2 |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Seam 2 Framework Search vendor "Redhat" for product "Jboss Seam 2 Framework" | 2.2.1 Search vendor "Redhat" for product "Jboss Seam 2 Framework" and version "2.2.1" | cr3 |
Affected
|