CVE-2018-12533: Red Hat RichFaces

Critical severity, CVSS 9.8. EPSS: 19% chance of exploitation in the next 30 days.

JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.

Affected products

  • Red Hat RichFaces: from 3.1.0, up to and including 3.3.4

Published 2018-06-18. Last modified 2026-06-17.