CVE-2018-14667: Red Hat JBoss RichFaces Framework
EPSS74.2%No. 682 of 1739 in KEV
CVE year2018~5 yrs before listing
Same vendor in KEV9
Same product1
| Field | Value |
|---|---|
| Vendor | Red Hat |
| Product | JBoss RichFaces Framework |
| Name | Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability |
| Added to KEV | 2023-09-28 |
| US federal due date | 2023-10-19 |
| Ransomware use | Unknown |
| CWE | CWE-94 |
CISA description
Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Red Hat JBoss RichFaces Framework vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-28.