'; } else{ echo ''; } echo '
|
|
|||
| Rule General Information |
|---|
| Release Date: | 2026-07-21 | |
| Rule Name: | JBoss RichFaces Paint2DResource EL Code Injection Vulnerability (CVE-2018-12533) | |
| Severity: | ||
| CVE ID: | ||
| Rule Protection Details |
|---|
| Description: | JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310. | |
| Impact: | Successful exploitation allows an attacker to execute arbitrary code on the target server, leading to complete system compromise, data theft, and further lateral movement in the network. | |
| Affected OS: | Windows, Linux, Others | |
| Reference: | CVE-2018-12533 |
|
| Solutions |
|---|
| Please refer to announcements or patches release by the vendor: http://richfaces.jboss.org |