Jboss EAP Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2014-0248 - Vulnerability Database

Jboss EAP Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2014-0248

Medium
Reference: CVE-2014-0248
Title: Jboss EAP Improper Control of Generation of Code (Code Injection) Vulnerability
Overview:

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0 JBoss Enterprise Application Platform (JBEAP) 5.2.0 and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header related to Seam logging.