EXPOSURES › CVE-2010-1871
CVE-2010-1871
HIGH ⌖ ON CISA KEV · EXPLOITEDJBoss Seam 2 in Red Hat Linux allows remote code execution when the Java Security Manager is misconfigured, and the flaw is actively exploited in the wild.
JBoss Seam 2 in Red Hat Linux contains a remote code execution vulnerability that can be triggered if the Java Security Manager is not properly configured. This is a high-severity issue because it allows attackers to execute arbitrary code on the server, leading to full system compromise. DIB organizations must ensure their Java Security Manager is correctly configured and apply patches for JBoss Seam 2 to prevent exploitation.
Shame score — The vulnerability is actively exploited in the wild and requires a specific misconfiguration to be triggered, indicating a significant gap in both patch management and security hardening.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, allows attackers to perform remote code execution. This vulnerability can only be exploited when the Java Security Manager is not properly configured.
| PRODUCT | STATUS |
|---|---|
| Red Hat OpenShift Service on AWS (ROSA) Red Hat |
In Process |