CVE-2010-1871
KEVlargeRemote Code Execution via EL Injection in Red Hat JBoss Seam 2 (JBoss EAP 4.3.0)
CISA: Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability
JBoss Seam 2 (jboss-seam2), as used in Red Hat JBoss Enterprise Application Platform (EAP) 4.3.0 for Red Hat Linux, is vulnerable to remote code execution caused by an input validation flaw (CWE-20) in its processing of Expression Language (EL) expressions. A remote attacker triggers the flaw by sending crafted input containing EL expressions that the Seam framework evaluates without sufficient validation; exploitation succeeds only when the Java Security Manager is not properly configured, which is the typical default. Successful exploitation lets the attacker run arbitrary code with the privileges of the JBoss server process, providing a foothold on the host and access to any back-end systems the application server can reach. Organizations still running legacy Red Hat JBoss EAP 4.3.0 / Seam 2 deployments, particularly internet-facing ones, are in scope, and the flaw is in the CISA Known Exploited Vulnerabilities (KEV) catalog, obliging U.S. federal agencies to apply vendor updates. It was added to KEV on 2021-12-10, confirming in-the-wild exploitation (ransomware use unknown); it carries a very high EPSS of 83.4% (100th percentile) and no public proof-of-concept is known.
What to do: Apply Red Hat's patched jboss-seam2 update for JBoss Enterprise Application Platform 4.3.0 per vendor instructions (RHSA-2010:0574); where immediate patching is not possible, properly configure the Java Security Manager for the JBoss JVM — the flaw is only exploitable when it is not properly configured — and restrict untrusted EL input and internet exposure of Seam-based applications. Inventory legacy JBoss EAP 4.x/Seam 2 hosts, prioritize internet-facing Linux servers given active Linux-targeting threats such as the SpeakUp backdoor, and check those hosts for signs of compromise. Remediation is required for U.S. federal agencies under CISA's KEV requirement (listed 2021-12-10).
| Red Hat JBoss Seam 2 (jboss-seam2) | JBoss Seam 2 as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux (specific fixed version not stated in source data; remediated via Red Hat' |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.
- Affected
- Red Hat JBoss Seam 2
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- Red Hat
- Products
- JBoss Seam 2
- Weakness
- CWE-20