CVE-2014-0248: Code Injection
It was found that org.jboss.seam.web.AuthenticationFilter class implementation used seam logging in an unsafe manner. A remote attacker could exploit this issue in order to gain arbitrary code execution by providing specifically crafted authentication headers.
Other sources
org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0248?
CVE-2014-0248 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2014-0248?
To fix CVE-2014-0248, upgrade to the latest patched version of Red Hat JBoss Enterprise Application Platform, JBoss Enterprise Web Platform, or JBoss Web Framework Kit.
Who is affected by CVE-2014-0248?
CVE-2014-0248 affects users of Red Hat JBoss Enterprise Application Platform version 5.2.0, JBoss Enterprise Web Platform version 5.2.0, and JBoss Web Framework Kit version 2.5.0.
What kind of attack can exploit CVE-2014-0248?
CVE-2014-0248 can be exploited by remote attackers who send specially crafted authentication headers to execute arbitrary code.
When was CVE-2014-0248 disclosed?
CVE-2014-0248 was disclosed in 2014, drawing attention to its security impact on affected systems.