Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:13094
HistoryJan 15, 2019 - 9:25 a.m.

Remote Code Execution (RCE)

2019-01-1509:25:47
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10

0.708 High

EPSS

Percentile

98.1%

richfaces is vulnerable to remote code execution (RCE) attacks. The vulnerability exists as the RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.