Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-12532

Опубликовано: 30 мая 2018
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.

Отчет

This issue does not affect the following Red Hat products, as they do not include the vulnerable version of the RichFaces component: Red Hat JBoss EAP 5.2 Red Hat JBoss Data Virtualization 6.4 Red Hat JBoss BRMS 5.3 Red Hat JBoss Operations Network 3.3

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 11RichFacesNot affected
Red Hat JBoss BRMS 5RichFacesNot affected
Red Hat JBoss Data Virtualization 6RichFacesNot affected
Red Hat JBoss Enterprise Application Platform 5RichFacesNot affected
Red Hat JBoss Enterprise Application Platform 6RichFacesNot affected
Red Hat JBoss Operations Network 3RichFacesNot affected
Red Hat JBoss SOA Platform 5RichFacesNot affected

Показывать по

Дополнительная информация

Статус:

Critical
Дефект:
CWE-94
https://bugzilla.redhat.com/show_bug.cgi?id=1584492RichFaces: Injection of arbitrary EL variable mapper allows to bypass mitigation of CVE-2015-0279 and thereby remote code execution

EPSS

Процентиль: 87%
0.03296
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.

CVSS3: 9.8
github
больше 3 лет назад

RichFaces vulnerable to Expression Language Injection

EPSS

Процентиль: 87%
0.03296
Низкий

9.8 Critical

CVSS3