EXPOSURES › CVE-2018-14667
CVE-2018-14667
HIGH ⌖ ON CISA KEV · EXPLOITEDRed Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
A remote attacker can execute malicious code via a chain of Java serialized objects, leading to unauthorized access. This vulnerability is actively exploited and should be patched immediately.
Shame score — Active exploitation and high severity of the vulnerability
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
| PRODUCT | STATUS |
|---|---|
| Red Hat OpenShift Service on AWS (ROSA) Red Hat |
In Process |