CVE-2018-12532: Red Hat RichFaces
Critical severity, CVSS 9.8. EPSS: 7% chance of exploitation in the next 30 days.
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Affected products
- Red Hat RichFaces: from 4.5.3, up to and including 4.5.17
Published 2018-06-18. Last modified 2026-06-17.