Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:24115
HistoryApr 10, 2020 - 12:46 a.m.

Arbitrary Code Execution

2020-04-1000:46:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
22

0.968 High

EPSS

Percentile

99.7%

jboss-seam2 is vulnerable to arbitrary code execution. The vulnerability exists as an input sanitization flaw was found in the way JBoss Seam processed certain parametrized JBoss Expression Language (EL) expressions. A remote attacker could use this flaw to execute arbitrary code via a URL, containing appended, specially-crafted expression language parameters, provided to certain applications based on the JBoss Seam framework.