A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of security impacts depending on the deserialization logic of these classes.
It was reported [1] that remote attackers can inject EL (Expression Language) via "do" parameter. This leads to remote Java method execution vulnerability.
[1]: https://issues.jboss.org/browse/RF-13977