JBoss Seam Expression Language (EL) CVE-2011-2196 Remote Code Execution Vulnerability
BID:48716
Info
JBoss Seam Expression Language (EL) CVE-2011-2196 Remote Code Execution Vulnerability
| Bugtraq ID: | 48716 |
| Class: | Unknown |
| CVE: |
CVE-2011-2196 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2011 12:00AM |
| Updated: | Jul 26 2013 01:24PM |
| Credit: | ObjectWorks+ Development Team at Nomura Research Institute |
| Vulnerable: |
Red Hat JBoss Enterprise Web Platform 5 EL6 Red Hat JBoss Enterprise Web Platform 5 EL5 Red Hat JBoss Enterprise Web Platform 5 EL4 Red Hat JBoss Enterprise Application Platform for RHEL 5 Server 5 Red Hat JBoss Enterprise Application Platform for RHEL 4ES 5 Red Hat JBoss Enterprise Application Platform for RHEL 4AS 5 Red Hat JBoss Enterprise Application Platform 4.3 EL5 Red Hat JBoss Enterprise Application Platform 4.3 EL4 Red Hat JBoss Enterprise Application Platform 4.3 Red Hat JBoss Enterprise Application Platform 5 EL6 JBoss Group JBoss Seam 2.0.2 JBoss Group JBoss Seam 2.0 GA JBoss Group JBoss Seam 2.0 CR3 JBoss Group JBoss Seam 2.0 CR2 JBoss Group JBoss Seam 2.0 CR1 JBoss Group JBoss Seam 2.0.2.SP1 HP Network Node Manager i 9.10 HP Network Node Manager i 9.0 |
| Not Vulnerable: | |
Discussion
JBoss Seam Expression Language (EL) CVE-2011-2196 Remote Code Execution Vulnerability
JBoss Seam is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application.
Note that the issue exists due to an incomplete fix for CVE-2011-1484.
JBoss Seam is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application.
Note that the issue exists due to an incomplete fix for CVE-2011-1484.
Exploit / POC
JBoss Seam Expression Language (EL) CVE-2011-2196 Remote Code Execution Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
JBoss Seam Expression Language (EL) CVE-2011-2196 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
JBoss Seam Expression Language (EL) CVE-2011-2196 Remote Code Execution Vulnerability
References:
References:
- JBoss Seam Homepage (JBoss Group)
- RHSA-2011:0945 JBoss Enterprise Web Platform 5.1.1 update (Red Hat)
- RHSA-2011:0946 JBoss Enterprise Application Platform 5.1.1 update (Red Hat)
- RHSA-2011:0949 JBoss Enterprise Application Platform 5.1.1 update (Red Hat)
- RHSA-2011:0951 jboss-seam security update (Red Hat)
- RHSA-2011:0952 JBoss Enterprise SOA Platform 4.3.0.CP05 and 5.1.0 security updat (Red Hat)