Skip to content
COOEY

EXPOSURES › CVE-2010-1871

CVE-2010-1871

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-1871 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 rceexploited-in-wildunpatched

JBoss Seam 2 in Red Hat Linux allows remote code execution when the Java Security Manager is misconfigured, and the flaw is actively exploited in the wild.

JBoss Seam 2 in Red Hat Linux contains a remote code execution vulnerability that can be triggered if the Java Security Manager is not properly configured. This is a high-severity issue because it allows attackers to execute arbitrary code on the server, leading to full system compromise. DIB organizations must ensure their Java Security Manager is correctly configured and apply patches for JBoss Seam 2 to prevent exploitation.

Shame score — The vulnerability is actively exploited in the wild and requires a specific misconfiguration to be triggered, indicating a significant gap in both patch management and security hardening.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Red Hat OpenShift Service on AWS (ROSA)
Red Hat
In Process