First published: Tue Dec 18 2007(Updated: )
The getRenderedEjbql method in the org.jboss.seam.framework.Query class in JBoss Seam 2.x before 2.0.0.CR3 allows remote attackers to inject and execute arbitrary EJBQL commands via the order parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat JBoss Seam 2 Framework | <=2.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-6433 has a high severity rating due to the potential for remote code execution through EJBQL injection.
To fix CVE-2007-6433, upgrade to JBoss Seam version 2.0.0.CR3 or later.
CVE-2007-6433 affects JBoss Seam versions prior to 2.0.0.CR3, specifically 2.x versions up to and including 2.0.0.
CVE-2007-6433 is a code injection vulnerability that allows attackers to execute arbitrary EJBQL commands.
Yes, CVE-2007-6433 can be exploited remotely, allowing attackers to inject malicious EJBQL commands.