In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.
Fix available through Seal Security. No upgrade required, protect your application instantly.
Fix without upgrading