Description
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2014-0793.html
http://rhn.redhat.com/errata/RHSA-2014-0785.html
http://rhn.redhat.com/errata/RHSA-2014-0792.html
http://rhn.redhat.com/errata/RHSA-2014-0791.html
http://www.securitytracker.com/id/1030457
http://secunia.com/advisories/59555
http://rhn.redhat.com/errata/RHSA-2014-0794.html
http://secunia.com/advisories/59346
http://secunia.com/advisories/59554
http://rhn.redhat.com/errata/RHSA-2015-1888.html
Related Vulnerabilities
CVE-2019-1003036 Vulnerability in maven package org.jenkins-ci.plugins:azure-vm-agents
CVE-2023-46589 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2014-7810 Vulnerability in maven package org.apache.tomcat:tomcat-jasper
CVE-2018-1999003 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2017-8032 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-uaa