CVE-2015-0279
RichFaces: Remote Command Execution via insufficient EL parameter sanitization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
JBoss RichFaces anterior a 4.5.4 permite a atacantes remotos inyectar expresiones del lenguaje de expresiones (EL) y ejecutar código Java arbitrario a través del parámetro do.
It was found that the 'do' parameter permitted expression language (EL) injection, which could allow a remote attacker to execute Java methods on an affected server.
Red Hat JBoss Web Framework Kit combines popular open source web frameworks into a single solution for Java applications. RichFaces is an open source framework that adds Ajax capability into existing JavaServer Faces applications. It was found that the 'do' parameter permitted expression language injection, which could allow a remote attacker to execute Java methods on an affected server.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-11-18 CVE Reserved
- 2015-03-25 CVE Published
- 2020-03-09 First Exploit
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
- CWE-95: Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
CAPEC
References (10)
URL | Tag | Source |
---|---|---|
http://jvn.jp/en/jp/JVN56297719/index.html | Third Party Advisory | |
http://jvndb.jvn.jp/en/contents/2015/JVNDB-2015-001959.html | Third Party Advisory | |
http://packetstormsecurity.com/files/153734/Tufin-Secure-Change-Remote-Code-Execution.html | X_refsource_misc |
|
http://packetstormsecurity.com/files/156663/Richsploit-RichFaces-Exploitation-Toolkit.html | X_refsource_misc |
|
http://seclists.org/fulldisclosure/2019/Jul/21 | Mailing List |
|
http://seclists.org/fulldisclosure/2020/Mar/21 | Mailing List |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/156663 | 2020-03-09 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://rhn.redhat.com/errata/RHSA-2015-0719.html | 2019-07-23 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1192140 | 2015-03-24 | |
https://access.redhat.com/security/cve/CVE-2015-0279 | 2015-03-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Richfaces Search vendor "Redhat" for product "Richfaces" | >= 4.0.0 <= 4.5.4 Search vendor "Redhat" for product "Richfaces" and version " >= 4.0.0 <= 4.5.4" | - |
Affected
|