CVE-2015-0279: Red Hat RichFaces

Medium severity, CVSS 6.8. EPSS: 3.9% chance of exploitation in the next 30 days.

JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.

Affected products

  • Red Hat RichFaces: from 4.0.0, up to and including 4.5.4

Published 2015-03-26. Last modified 2026-06-17.