ZeroHour

CVE-2010-1871

KEVlarge

Remote Code Execution via EL Injection in Red Hat JBoss Seam 2 (JBoss EAP 4.3.0)

CISA: Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability

CVSS
EPSS
83%p100
Published
KEV added
AI analysis

JBoss Seam 2 (jboss-seam2), as used in Red Hat JBoss Enterprise Application Platform (EAP) 4.3.0 for Red Hat Linux, is vulnerable to remote code execution caused by an input validation flaw (CWE-20) in its processing of Expression Language (EL) expressions. A remote attacker triggers the flaw by sending crafted input containing EL expressions that the Seam framework evaluates without sufficient validation; exploitation succeeds only when the Java Security Manager is not properly configured, which is the typical default. Successful exploitation lets the attacker run arbitrary code with the privileges of the JBoss server process, providing a foothold on the host and access to any back-end systems the application server can reach. Organizations still running legacy Red Hat JBoss EAP 4.3.0 / Seam 2 deployments, particularly internet-facing ones, are in scope, and the flaw is in the CISA Known Exploited Vulnerabilities (KEV) catalog, obliging U.S. federal agencies to apply vendor updates. It was added to KEV on 2021-12-10, confirming in-the-wild exploitation (ransomware use unknown); it carries a very high EPSS of 83.4% (100th percentile) and no public proof-of-concept is known.

What to do: Apply Red Hat's patched jboss-seam2 update for JBoss Enterprise Application Platform 4.3.0 per vendor instructions (RHSA-2010:0574); where immediate patching is not possible, properly configure the Java Security Manager for the JBoss JVM — the flaw is only exploitable when it is not properly configured — and restrict untrusted EL input and internet exposure of Seam-based applications. Inventory legacy JBoss EAP 4.x/Seam 2 hosts, prioritize internet-facing Linux servers given active Linux-targeting threats such as the SpeakUp backdoor, and check those hosts for signs of compromise. Remediation is required for U.S. federal agencies under CISA's KEV requirement (listed 2021-12-10).

Affected
Red Hat JBoss Seam 2 (jboss-seam2)JBoss Seam 2 as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux (specific fixed version not stated in source data; remediated via Red Hat'
Estimated exposure
largeon the order of tens of thousands of legacy JBoss EAP 4.x / Seam 2 deployments worldwide, with the internet-exposed subset likely in the thousands (exact count… — Estimated from public internet scans that have repeatedly indexed tens of thousands of exposed JBoss application servers and the large legacy enterprise install base of Red Hat JBoss EAP 4.x, in which jboss-seam2 shipped with EAP 4.3.0;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.

CISA Known Exploited Vulnerability
Affected
Red Hat JBoss Seam 2
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Red Hat
Products
JBoss Seam 2
Weakness
CWE-20

In the news