Description
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2014-0785.html
http://rhn.redhat.com/errata/RHSA-2014-0791.html
http://rhn.redhat.com/errata/RHSA-2014-0792.html
http://rhn.redhat.com/errata/RHSA-2014-0793.html
http://rhn.redhat.com/errata/RHSA-2014-0794.html
http://rhn.redhat.com/errata/RHSA-2015-1888.html
http://secunia.com/advisories/59346
http://secunia.com/advisories/59554
http://secunia.com/advisories/59555
http://www.securitytracker.com/id/1030457
Related Vulnerabilities
CVE-2012-5887 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-41931 Vulnerability in maven package org.xwiki.platform:xwiki-platform-icon-ui
CVE-2023-35142 Vulnerability in maven package com.checkmarx.jenkins:checkmarx
CVE-2016-6801 Vulnerability in maven package org.apache.jackrabbit:jackrabbit-webdav
CVE-2020-16015 Vulnerability in maven package org.webjars.npm:electron