JBoss Seam Framework 2 deployments were exposed to remote-code-execution risk through both CVE-2010-1871 and outdated bundled Java web components. Seam 2.3.1.Final included Mojarra 2.1.7 and RichFaces 4.3.3.Final, creating a layered dependency problem in which applications could remain vulnerable even when their direct framework version appeared current.
Known inherited flaws included Mojarra path traversal tracked as CVE-2013-3827 and RichFaces Java deserialization remote code execution tracked as CVE-2013-2165. JBoss reportedly stated that Seam, nearing end of maintenance, would receive fixes only for important or high-severity issues; organizations using Seam 2 should inventory transitive components, upgrade or replace vulnerable dependencies, and isolate or retire unsupported deployments.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
The author submitted several Seam Framework vulnerabilities to security@jboss.org. JBoss reportedly said it would address Seam issues only when they were important or high-severity because the framework was nearing the end of maintenance.
The author observed Mojarra-related indicators on an Apple website and reported that a 2013 JSF path-traversal vulnerability worked against it during testing. The sensitive-file-access proof of concept no longer worked when the author later sought to report the issue.
The author reported that Seam Framework 2 used an older RichFaces version affected by CVE-2013-2165. Its exposed /a4j/ URL pattern could pass parameters to readObject, enabling remote code execution through Java deserialization.
The author modified a CVE-2013-3827 proof of concept and reproduced sensitive-file reading against the latest Seam Framework 2 release, which bundled Mojarra 2.1.7.
CVE-2010-1871 was identified as an expression-language injection vulnerability in the JBoss Seam Framework that can lead to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.