CVE-2018-14667
KEVCRITICAL 9.8EPSS 74.2%
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H - CVSS v3.0
- 9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 74.17% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2023-09-28
- Published
- 2018-11-06
- Updated
- 2025-10-21
Proof-of-concept exploits (8)
- http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.html
- http://seclists.org/fulldisclosure/2020/Mar/21
- Venscor/CVE-2018-14667-poc8★ · 2019-09-24
- nareshmail/cve-2018-146670★ · 2018-11-17
- quandqn/cve-2018-146671★ · 2019-07-29
- r00t4dm/CVE-2018-146671★ · 2018-11-29
- syriusbughunt/CVE-2018-1466750★ · 2018-11-30
- zeroto01/CVE-2018-146672★ · 2018-11-23