CVE-2018-12532 is a critical vulnerability affecting JBoss RichFaces versions 4.5.3 through 4.5.17, allowing unauthenticated remote attackers to execute arbitrary Java code. This is achieved by injecting an arbitrary Expression Language (EL) variable mapper through a MediaOutputResource request. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While no public exploit intelligence or active exploitation has been observed, and community discussion is minimal, the high FAUCET Risk Score of 83/100 indicates its potential severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.5.3, <= 4.5.17CPE matchmatch criteria | cpe:2.3:a:redhat:richfaces:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.