Red.Hat.JBoss.RichFaces.UserResource.EL.Code.Injection
Description
This indicates an attack attempt to exploit a Code Injection vulnerability in JBoss RichFaces.
The vulnerability is due to insufficient sanitizing of user supplied URI inputs into the application. A remote attacker can exploit this to send a crafted query to execute arbitrary commands on a vulnerable server.
Affected Products
RichFaces Framework 3.X through 3.3.4
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor:
https://access.redhat.com/security/cve/CVE-2018-14667
Coverage
| IPS (Regular DB) | |
| IPS (Extended DB) |
Version Updates
| Date | Version | Status | Detail |
|---|---|---|---|
| 2021-02-08 | 17.012 |
New
|