CVE-2018-14667

Confirmed PUBLISHED

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote,...

[UNKNOWN] · RichFaces
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical

At a Glance

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

nessus_scanner java cisa
CVE Published
Nov 06, 2018
Exploitation Reported
Sep 28, 2023
CVSS
9.8 Critical
EPSS
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
[UNKNOWN]
RichFaces

affected 3.X through 3.3.4

Affected

CVE References

  • RHSA-2018:3519 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:3519
  • RHSA-2018:3581 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:3581
  • RHSA-2018:3518 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:3518
  • RHSA-2018:3517 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2018:3517
  • 1042037 securitytracker.com · VDB Entry http://www.securitytracker.com/id/1042037
Show 3 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.