CVE-2018-14667

CVE Published 2018-11-06
Related CWE(s) CWE-94: Improper Control of Generation of Code ('Code Injection')
Related Vendor(s) redhat
Related Product(s) richfaces, enterprise_linux
Exploitation Reported (CISA KEV) 2023-09-28
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References