← Browse

CVE-2018-14667

Act now ● On CISA KEV — actively exploited

Actively exploited — on the CISA KEV list.

CVSS base
EPSS — probability of exploitation (30 days)
74.2%
99.5th percentile
CISA KEV
Listed
Added 2023-09-28 · patch by 2023-10-19
Weakness / dates
Published — · modified —

Description

Red Hat JBoss RichFaces Framework contains an expression language injection vulnerability via the UserResource resource. A remote, unauthenticated attacker could exploit this vulnerability to execute malicious code using a chain of Java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

Official: NVD · CVE.org