Upstream information
Description
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: this is only a vulnerability when the Java Security Manager is not properly configured.SUSE information
Overall state of this security issue: Does not affect SUSE products
No SUSE Bugzilla entries cross referenced.SUSE Security Advisories:
- TID000019403, published Wed Mar 18 21:51:34 CET 2020
- TID7023707, published Tue Feb 12 18:55:45 CET 2019
SUSE Timeline for this CVE
CVE page created: Tue Jul 9 17:09:34 2013CVE page last modified: Tue Jul 1 12:17:11 2025