PT-2011-3676 · Red Hat · Jboss Seam 2+3

David Jorm

·

Published

2011-07-27

·

Updated

2023-02-13

·

CVE-2011-2196

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JBoss Seam 2 framework versions 2.2.x and earlier Red Hat JBoss Enterprise SOA Platform versions 4.3.0.CP05 and 5.1.0 JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) versions 4.3.0, 4.3.0.CP09, and 5.1.1 JBoss Enterprise Web Platform version 5.1.1
Description The issue arises from the improper restriction of Expression Language (EL) statements in FacesMessages during page exception handling in the JBoss Seam 2 framework. This allows remote attackers to execute arbitrary Java code via a crafted URL to an application.
Recommendations For JBoss Seam 2 framework versions 2.2.x and earlier, consider restricting the use of Expression Language statements in FacesMessages during page exception handling until a proper fix is applied. For Red Hat JBoss Enterprise SOA Platform versions 4.3.0.CP05 and 5.1.0, update to a version that includes the complete fix for the issue. For JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) versions 4.3.0, 4.3.0.CP09, and 5.1.1, update to a version that includes the complete fix for the issue. For JBoss Enterprise Web Platform version 5.1.1, update to a version that includes the complete fix for the issue. As a temporary workaround, consider disabling the use of Expression Language statements in FacesMessages during page exception handling to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2011-2196
RHSA-2011:0945
RHSA-2011:0946
RHSA-2011:0947
RHSA-2011:0948
RHSA-2011:0950

Affected Products

Red Hat Jboss Enterprise Application Platform
Jboss Enterprise Portal Platform
Jboss Enterprise Web Platform
Jboss Seam 2