JBoss Seam Parameterized EL Expressions Remote Code Execution Vulnerability
Data de publicação: 09 novembro 2016
Schweregrad: : Medium
Descrição
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly sanitize inputs for JBoss Expression Language (EL) expressions, which allows remote attackers to execute arbitrary code via a crafted URL. NOTE: The vulnerability exists only when the Java Security Manager is not configured properly.
Exposição das informações
Apply associated Trend Micro DPI Rules.
Solução
Trend Micro Deep Security DPI Rule Number: 1007522