6.8
CVSSv2

CVE-2015-0279

Published: 26/03/2015 Updated: 23/07/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

JBoss RichFaces prior to 4.5.4 allows remote malicious users to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat richfaces

Vendor Advisories

It was found that the 'do' parameter permitted expression language (EL) injection, which could allow a remote attacker to execute Java methods on an affected server ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> RichFaces exploitation toolkit <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Red Timmy Security &lt;pub ...
<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Tufin SecureChange uses Richfaces 435, vulnerable to CVE-2015-0279 (unauthenticated RCE) <!--X-Subject-Header-End--> ...

Github Repositories

Cisco Umbrella Reporting Use Cisco Umbrella's Reporting to monitor your Umbrella integration and gain a better understanding of your Umbrella usage Gain insights into request activity and blocked activity, determining which of your identities are generating blocked requests Reports help build actionable intelligence in addressing security threats including changes in usa