First published: Thu Feb 12 2015(Updated: )
It was reported [1] that remote attackers can inject EL (Expression Language) via "do" parameter. This leads to remote Java method execution vulnerability. [1]: <a href="https://issues.jboss.org/browse/RF-13977">https://issues.jboss.org/browse/RF-13977</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Richfaces | >=4.0.0<=4.5.4 | |
redhat/RichFaces | <4.5.4 | 4.5.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.