Redhat

Richfaces

6 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warning
  • EPSS 88.86%
  • Published 06.11.2018 22:29:00
  • Last modified 27.01.2025 21:56:01

The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via ...

Exploit
  • EPSS 3.47%
  • Published 18.06.2018 12:29:00
  • Last modified 21.11.2024 03:45:22

JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.

  • EPSS 73.98%
  • Published 18.06.2018 12:29:00
  • Last modified 21.11.2024 03:45:22

JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData...

  • EPSS 6.51%
  • Published 26.03.2015 14:59:00
  • Last modified 12.04.2025 10:46:40

JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.

Exploit
  • EPSS 0.64%
  • Published 31.03.2014 14:58:19
  • Last modified 12.04.2025 10:46:40

The doFilter function in webapp/PushHandlerFilter.java in JBoss RichFaces 4.3.4, 4.3.5, and 5.x allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a large number of malformed atmosphere push requests...

  • EPSS 25.71%
  • Published 23.07.2013 11:03:11
  • Last modified 11.04.2025 00:51:21

ResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss Web Platform through 5.2.0, Red Hat JBoss Enterprise Application Platform through 4.3.0 CP10 and 5.x through 5.2.0...