CVE-2014-0248: Red Hat JBoss Enterprise Application Platform

Medium severity, CVSS 6.8. EPSS: 3.5% chance of exploitation in the next 30 days.

org.jboss.seam.web.AuthenticationFilter in Red Hat JBoss Web Framework Kit 2.5.0, JBoss Enterprise Application Platform (JBEAP) 5.2.0, and JBoss Enterprise Web Platform (JBEWP) 5.2.0 allows remote attackers to execute arbitrary code via a crafted authentication header, related to Seam logging.

Affected products

  • Red Hat JBoss Enterprise Application Platform: version 5.2.0 only
  • Red Hat JBoss Enterprise Web Platform: version 5.2.0 only
  • Red Hat JBoss Web Framework Kit: version 2.5.0 only

Published 2014-07-07. Last modified 2026-06-17.