CyberSec.Space Logo
返回 CVE 浏览器

CVE-2018-14667

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score69.4580%
EPSS Percentile87.37th
Published2018年11月6日
Last Modified2025年11月3日

Vulnerability Description

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

Affected Platforms (CPE)

📦
Redhat

Richfaces

>= 3.1.0 and <= 3.3.4
💻
Redhat

Enterprise Linux

= 5.0
💻
Redhat

Enterprise Linux

= 6.0

References & Advisories

相关漏洞威胁