Lucene search

K
jvnJapan Vulnerability NotesJVN:38787103
HistoryJul 19, 2013 - 12:00 a.m.

JVN#38787103: JBoss RichFaces vulnerable to remote code execution

2013-07-1900:00:00
Japan Vulnerability Notes
jvn.jp
56

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.1 Low

EPSS

Percentile

94.9%

JBoss RichFaces is a framework for integrating Ajax into web applications. JBoss RichFaces applications contain a deserialization interface where end users may provide input. This interface may deserialize untrusted data, which may lead to arbitrary code execution.

Impact

When specially crafted input is processed, arbitrary files may be written or arbitrary code may be executed on the application server.

Solution

Apply a patch
Apply the appropriate patch according to the information provided by the developer.

Products Affected

RichFaces applications that are created using the following versions are affected:

  • RichFaces 5.x
  • RichFaces 4.x
  • RichFaces 3.x

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

0.1 Low

EPSS

Percentile

94.9%