Back

MEDIUM

RichFaces: Remote Command Execution via insufficient EL parameter sanitization

Published Mar 26, 2015

Description

JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.

Affected products

Remediation

Red Hat statement

This issue did not affect any version of Red Hat JBoss Enterprise Application Platform 5 as they did not include the vulnerable version of the RichFaces component. JBoss EAP 5.x includes versions 3.3.1.x of RichFaces; this vulnerability was introduced in version 4.x of RichFaces.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 26, 2015
Updated Aug 6, 2024
Reserved Nov 18, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Mar 24, 2015