RedHat Richfaces 3.3.4

CPE Details

RedHat Richfaces 3.3.4
3.3.4
2013-07-23
11h46 +00:00
2013-07-24
12h15 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:richfaces:3.3.4:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

richfaces

Version

3.3.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2018-14667 2018-11-06 22h00 +00:00 The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
9.8
Critical
CVE-2018-12533 2018-06-18 10h00 +00:00 JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.
9.8
Critical