Skip to main content

Vendor/product archive

redhat / richfaces CVEs

Beta · best-effort

6 CVEs tagged to redhat / richfaces3 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2018-14667

Published Nov 6, 2018

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-12533

Published Jun 18, 2018

JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring i…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-12532

Published Jun 18, 2018

JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2015-0279

Published Mar 26, 2015

JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2165

Published Jul 23, 2013

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss E…

CVSS 7.5 · High
Showing 1-6 of 6 CVEsPage 1 of 1