CVE-2018-14667
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
74.2%
99.5th percentile
CISA KEV
Listed
Added 2023-09-28 · patch by 2023-10-19
Weakness / dates
—
Published — · modified —
Description
Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.