Exploited Vulnerabilities Daily
🌐 English

Home › Red Hat

CVE-2018-14667: Red Hat JBoss RichFaces Framework

EPSS74.2%No. 682 of 1739 in KEV
CVE year2018~5 yrs before listing
Same vendor in KEV9
Same product1
FieldValue
VendorRed Hat
ProductJBoss RichFaces Framework
NameRed Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
Added to KEV2023-09-28
US federal due date2023-10-19
Ransomware useUnknown
CWECWE-94

CISA description

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

NVD — CVE-2018-14667

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A Red Hat JBoss RichFaces Framework vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-28.