PT-2018-12653 · Red Hat · Red Hat Jboss Richfaces Framework

·

CVE-2018-14667

·

Published

2018-11-06

·

Updated

2025-11-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RichFaces Framework versions 3.X through 3.3.4
Description The RichFaces Framework is susceptible to Expression Language (EL) injection through the UserResource resource. A remote, unauthenticated attacker can potentially execute arbitrary code by exploiting a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData. This issue is currently being exploited in attacks, as indicated by CISA advisories.
Recommendations Versions prior to 3.4 are affected.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14667
GHSA-J7MW-7CRR-658V
RHSA-2018:3517

Affected Products

Red Hat Jboss Richfaces Framework