PT-2018-12653 · Red Hat · Red Hat Jboss Richfaces Framework
Joao Filho Matos Figueiredo
+1
·
Published
2018-11-06
·
Updated
2025-11-03
·
CVE-2018-14667
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RichFaces Framework versions 3.X through 3.3.4
Description
The RichFaces Framework is susceptible to Expression Language (EL) injection through the UserResource resource. A remote, unauthenticated attacker can potentially execute arbitrary code by exploiting a chain of Java serialized objects via
org.ajax4jsf.resource.UserResource$UriData. This issue is currently being exploited in attacks, as indicated by CISA advisories.Recommendations
Versions prior to 3.4 are affected.
Exploit
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat Jboss Richfaces Framework