{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Critical"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2018/cve-2018-14667.json"
      }
    ],
    "title": "RichFaces: Expression Language injection via UserResource allows for unauthenticated remote code execution",
    "tracking": {
      "current_release_date": "2025-11-21T13:56:03+00:00",
      "generator": {
        "date": "2025-11-21T13:56:03+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "4.6.12"
        }
      },
      "id": "CVE-2018-14667",
      "initial_release_date": "2018-11-06T18:44:00+00:00",
      "revision_history": [
        {
          "date": "2018-11-06T18:44:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2025-01-27T22:00:11+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2025-11-21T13:56:03+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "JBoss Developer Studio 11",
                "product": {
                  "name": "JBoss Developer Studio 11",
                  "product_id": "jboss_developer_studio_11",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_dev_studio:11."
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "JBoss Developer Studio 11"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss Operations Network 3",
                "product": {
                  "name": "Red Hat JBoss Operations Network 3",
                  "product_id": "red_hat_jboss_operations_network_3",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_operations_network:3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Operations Network 3"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "JBoss Enterprise BRMS Platform 5.3",
                "product": {
                  "name": "JBoss Enterprise BRMS Platform 5.3",
                  "product_id": "JBoss Enterprise BRMS Platform 5.3",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_brms_platform:5.3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Decision Manager"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss SOA Platform 5.3",
                "product": {
                  "name": "Red Hat JBoss SOA Platform 5.3",
                  "product_id": "Red Hat JBoss SOA Platform 5.3",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_soa_platform:5.3"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss SOA Platform"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat JBoss EAP 5",
                "product": {
                  "name": "Red Hat JBoss EAP 5",
                  "product_id": "Red Hat JBoss EAP 5",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
                  "product_id": "5Server-JBEAP-5",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el5"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server",
                "product": {
                  "name": "Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server",
                  "product_id": "6Server-JBEAP-5",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:jboss_enterprise_application_platform:5::el6"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat JBoss Enterprise Application Platform"
          },
          {
            "category": "product_version",
            "name": "RichFaces",
            "product": {
              "name": "RichFaces",
              "product_id": "RichFaces"
            }
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                "product": {
                  "name": "richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_id": "richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-root@3.3.1-9.SP3_patch_03.ep5.el5?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                "product": {
                  "name": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_id": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces@3.3.1-9.SP3_patch_03.ep5.el5?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                "product": {
                  "name": "richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_id": "richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-docs@3.3.1-9.SP3_patch_03.ep5.el5?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                "product": {
                  "name": "richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_id": "richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-cdk@3.3.1-9.SP3_patch_03.ep5.el5?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                "product": {
                  "name": "richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_id": "richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-ui@3.3.1-9.SP3_patch_03.ep5.el5?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                "product": {
                  "name": "richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_id": "richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-framework@3.3.1-9.SP3_patch_03.ep5.el5?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                "product": {
                  "name": "richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_id": "richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-demo@3.3.1-9.SP3_patch_03.ep5.el5?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                "product": {
                  "name": "richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_id": "richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-root@3.3.1-6.SP3_patch_03.ep5.el6?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                "product": {
                  "name": "richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_id": "richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-demo@3.3.1-6.SP3_patch_03.ep5.el6?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                "product": {
                  "name": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_id": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces@3.3.1-6.SP3_patch_03.ep5.el6?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                "product": {
                  "name": "richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_id": "richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-framework@3.3.1-6.SP3_patch_03.ep5.el6?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                "product": {
                  "name": "richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_id": "richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces-ui@3.3.1-6.SP3_patch_03.ep5.el6?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src",
                "product": {
                  "name": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src",
                  "product_id": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces@3.3.1-9.SP3_patch_03.ep5.el5?arch=src"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src",
                "product": {
                  "name": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src",
                  "product_id": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/richfaces@3.3.1-6.SP3_patch_03.ep5.el6?arch=src"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "src"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
          "product_id": "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch"
        },
        "product_reference": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
        "relates_to_product_reference": "5Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
          "product_id": "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src"
        },
        "product_reference": "richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src",
        "relates_to_product_reference": "5Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
          "product_id": "5Server-JBEAP-5:richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch"
        },
        "product_reference": "richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
        "relates_to_product_reference": "5Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
          "product_id": "5Server-JBEAP-5:richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch"
        },
        "product_reference": "richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
        "relates_to_product_reference": "5Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
          "product_id": "5Server-JBEAP-5:richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch"
        },
        "product_reference": "richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
        "relates_to_product_reference": "5Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
          "product_id": "5Server-JBEAP-5:richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch"
        },
        "product_reference": "richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
        "relates_to_product_reference": "5Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
          "product_id": "5Server-JBEAP-5:richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch"
        },
        "product_reference": "richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
        "relates_to_product_reference": "5Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 5 Server",
          "product_id": "5Server-JBEAP-5:richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch"
        },
        "product_reference": "richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
        "relates_to_product_reference": "5Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server",
          "product_id": "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch"
        },
        "product_reference": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
        "relates_to_product_reference": "6Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server",
          "product_id": "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src"
        },
        "product_reference": "richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src",
        "relates_to_product_reference": "6Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server",
          "product_id": "6Server-JBEAP-5:richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch"
        },
        "product_reference": "richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
        "relates_to_product_reference": "6Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server",
          "product_id": "6Server-JBEAP-5:richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch"
        },
        "product_reference": "richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
        "relates_to_product_reference": "6Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server",
          "product_id": "6Server-JBEAP-5:richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch"
        },
        "product_reference": "richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
        "relates_to_product_reference": "6Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch as a component of Red Hat JBoss Enterprise Application Platform 5 for RHEL 6 Server",
          "product_id": "6Server-JBEAP-5:richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch"
        },
        "product_reference": "richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
        "relates_to_product_reference": "6Server-JBEAP-5"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "RichFaces as a component of JBoss Developer Studio 11",
          "product_id": "jboss_developer_studio_11:RichFaces"
        },
        "product_reference": "RichFaces",
        "relates_to_product_reference": "jboss_developer_studio_11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "RichFaces as a component of Red Hat JBoss Operations Network 3",
          "product_id": "red_hat_jboss_operations_network_3:RichFaces"
        },
        "product_reference": "RichFaces",
        "relates_to_product_reference": "red_hat_jboss_operations_network_3"
      }
    ]
  },
  "vulnerabilities": [
    {
      "acknowledgments": [
        {
          "names": [
            "Joao Filho Matos Figueiredo"
          ]
        }
      ],
      "cve": "CVE-2018-14667",
      "cwe": {
        "id": "CWE-94",
        "name": "Improper Control of Generation of Code ('Code Injection')"
      },
      "discovery_date": "2018-10-15T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_jboss_operations_network_3:RichFaces"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "1639139"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "RichFaces: Expression Language injection via UserResource allows for unauthenticated remote code execution",
          "title": "Vulnerability summary"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
          "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src",
          "5Server-JBEAP-5:richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
          "5Server-JBEAP-5:richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
          "5Server-JBEAP-5:richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
          "5Server-JBEAP-5:richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
          "5Server-JBEAP-5:richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
          "5Server-JBEAP-5:richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
          "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
          "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src",
          "6Server-JBEAP-5:richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
          "6Server-JBEAP-5:richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
          "6Server-JBEAP-5:richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
          "6Server-JBEAP-5:richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
          "JBoss Enterprise BRMS Platform 5.3",
          "Red Hat JBoss EAP 5",
          "Red Hat JBoss SOA Platform 5.3"
        ],
        "known_affected": [
          "jboss_developer_studio_11:RichFaces"
        ],
        "known_not_affected": [
          "red_hat_jboss_operations_network_3:RichFaces"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2018-14667"
        },
        {
          "category": "external",
          "summary": "RHBZ#1639139",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1639139"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2018-14667",
          "url": "https://www.cve.org/CVERecord?id=CVE-2018-14667"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2018-14667",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2018-14667"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        }
      ],
      "release_date": "2018-11-06T18:44:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2018-11-06T19:05:38+00:00",
          "details": "Before applying this update, back up your existing JBoss Enterprise Application Platform installation (including all applications and configuration files) and make sure all previously-released errata relevant to your system have been applied.",
          "product_ids": [
            "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src",
            "5Server-JBEAP-5:richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src",
            "6Server-JBEAP-5:richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2018:3517"
        },
        {
          "category": "vendor_fix",
          "date": "2018-11-13T09:39:48+00:00",
          "details": "The References section of this erratum contains a download link (you must\nlog in to download the update). Before applying the update, back up your\nexisting Red Hat JBoss BRMS installation (including its databases,\napplications, configuration files, and so on).\n\nNote that it is recommended to halt the Red Hat JBoss BRMS server by\nstopping the JBoss Application Server process before installing this\nupdate, and then after installing the update, restart the Red Hat JBoss\nBRMS server by starting the JBoss Application Server process.",
          "product_ids": [
            "JBoss Enterprise BRMS Platform 5.3"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2018:3581"
        },
        {
          "category": "vendor_fix",
          "date": "2018-11-06T18:53:45+00:00",
          "details": "Before applying this update, back up your existing Red Hat JBoss Enterprise Application Platform installation and deployed applications.\n\nThe References section of this erratum contains a download link (you must log in to download the update).\n\nThe JBoss server process must be restarted for the update to take effect.",
          "product_ids": [
            "Red Hat JBoss EAP 5"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2018:3518"
        },
        {
          "category": "vendor_fix",
          "date": "2018-11-07T01:49:07+00:00",
          "details": "The References section of this erratum contains a download link (you must\nlog in to download the update). Before applying the update, back up your\nexisting Red Hat JBoss SOA Platform installation (including its databases,\napplications, configuration files, and so on).\n\nNote that it is recommended to halt the Red Hat JBoss SOA Platform server\nby stopping the JBoss Application Server process before installing this\nupdate, and then after installing the update, restart the Red Hat JBoss SOA\nPlatform server by starting the JBoss Application Server process.",
          "product_ids": [
            "Red Hat JBoss SOA Platform 5.3"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2018:3519"
        },
        {
          "category": "no_fix_planned",
          "details": "Out of support scope",
          "product_ids": [
            "jboss_developer_studio_11:RichFaces"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.0"
          },
          "products": [
            "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src",
            "5Server-JBEAP-5:richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src",
            "6Server-JBEAP-5:richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "JBoss Enterprise BRMS Platform 5.3",
            "Red Hat JBoss EAP 5",
            "Red Hat JBoss SOA Platform 5.3",
            "jboss_developer_studio_11:RichFaces",
            "red_hat_jboss_operations_network_3:RichFaces"
          ]
        }
      ],
      "threats": [
        {
          "category": "exploit_status",
          "date": "2023-09-28T00:00:00+00:00",
          "details": "CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
        },
        {
          "category": "impact",
          "details": "Critical",
          "product_ids": [
            "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-0:3.3.1-9.SP3_patch_03.ep5.el5.src",
            "5Server-JBEAP-5:richfaces-cdk-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-demo-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-docs-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-framework-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-root-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "5Server-JBEAP-5:richfaces-ui-0:3.3.1-9.SP3_patch_03.ep5.el5.noarch",
            "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-0:3.3.1-6.SP3_patch_03.ep5.el6.src",
            "6Server-JBEAP-5:richfaces-demo-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-framework-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-root-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "6Server-JBEAP-5:richfaces-ui-0:3.3.1-6.SP3_patch_03.ep5.el6.noarch",
            "JBoss Enterprise BRMS Platform 5.3",
            "Red Hat JBoss EAP 5",
            "Red Hat JBoss SOA Platform 5.3",
            "jboss_developer_studio_11:RichFaces",
            "red_hat_jboss_operations_network_3:RichFaces"
          ]
        }
      ],
      "title": "RichFaces: Expression Language injection via UserResource allows for unauthenticated remote code execution"
    }
  ]
}