org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.
| Software | From | Fixed in |
|---|---|---|
| redhat / jboss_enterprise_web_platform | 5.2.0 | 5.2.0.x |
| redhat / jboss_enterprise_application_platform | 5.2.0 | 5.2.0.x |
| redhat / jboss_web_framework_kit | 2.5.0 | 2.5.0.x |