VulnerabilityModified
CVE-2015-0279
JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
MEDIUM 6.8EPSS 3.93%
Does this matter?
Lower severity and a low EPSS score (3.93%). Track it; it rarely justifies an emergency change on its own.
Description
JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.93% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- redhat/richfaces
- Source
- secalert@redhat.com
References
- http://jvn.jp/en/jp/JVN56297719/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-001959.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/153734/Tufin-Secure-Change-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.html
- http://rhn.redhat.com/errata/RHSA-2015-0719.htmlBroken Link, Vendor Advisory
- http://seclists.org/fulldisclosure/2019/Jul/21
- http://seclists.org/fulldisclosure/2020/Mar/21
- https://bugzilla.redhat.com/show_bug.cgi?id=1192140Issue Tracking, Vendor Advisory
- http://jvn.jp/en/jp/JVN56297719/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-001959.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/153734/Tufin-Secure-Change-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.html
- http://rhn.redhat.com/errata/RHSA-2015-0719.htmlBroken Link, Vendor Advisory
- http://seclists.org/fulldisclosure/2019/Jul/21
- http://seclists.org/fulldisclosure/2020/Mar/21
- https://bugzilla.redhat.com/show_bug.cgi?id=1192140Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.