Remote code execution in Red Hat JBoss RichFaces

Published: 2018-11-07 15:59:40
Severity High
Patch available YES
Number of vulnerabilities 1
CVE ID CVE-2018-14667
CVSSv3 8.7 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CWE ID CWE-502
Exploitation vector Network
Public exploit N/A
Vulnerable software JBoss Richfaces
Vulnerable software versions JBoss Richfaces 3.3.4
JBoss Richfaces 3.3.3
JBoss Richfaces 3.3.2

Show more

Vendor URL Red Hat Inc.

Security Advisory

1) Deserialization of untrusted data

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to deserialization of untrusted data. A remote unauthenticated attacker can send a specially crafted UserResource RichFaces expression language that contains a tainted java serialized object org.ajax4jsf.resource.UserResource$UriData expression, trigger deserialization after clearing white list protections and execute arbitrary code with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Remediation

Install update from vendor's website.

External links

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14667

Back to List