Skip to content
COOEY

EXPOSURES › CVE-2018-14667

CVE-2018-14667

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-09-28 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-14667 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability

A remote attacker can execute malicious code via a chain of Java serialized objects, leading to unauthorized access. This vulnerability is actively exploited and should be patched immediately.

Shame score — Active exploitation and high severity of the vulnerability

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Red Hat OpenShift Service on AWS (ROSA)
Red Hat
In Process