A code execution vulnerability has been discovered in JBoss SOA RTgov. The flaw allows remote authenticated attackers to submit arbitrary Java code in MVEL expressions submitted through RTgov, the code would be executed within the security context of the application server.
Red Hat JBoss SOA Platform is the next-generation ESB and business process<br>automation infrastructure. Red Hat JBoss SOA Platform allows IT to leverage<br>existing (MoM and EAI), modern (SOA and BPM-Rules), and future (EDA and<br>CEP) integration methodologies to dramatically improve business process<br>execution speed and quality.<br>This asynchronous patch is a security update for the RichFaces package in Red Hat JBoss SOA Platform 5.3.1.<br>Security Fix(es):<br><li> RichFaces: Expression Language injection via UserResource allows for unauthenticated remote code execution (CVE-2018-14667)</li> See <a href="https://access.redhat.com/solutions/3660371" target="blank">https://access.redhat.com/solutions/3660371</a> for specific information regarding this flaw.<br>For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.<br>Red Hat would like to thank Joao Filho Matos Figueiredo for reporting this issue.