CVE-2018-14667 | RichFaces Framework up to 3.3.4 org.ajax4jsf.resource.UserResource$UriData Serialized Object code injection (RHSA-2018:3517 / Nessus ID 118943)
A vulnerability, which was classified as critical, has been found in RichFaces Framework up to 3.3.4. This issue affects some unknown processing of the component org.ajax4jsf.resource.UserResource$UriData. The manipulation as part of Serialized Object leads to code injection.
The identification of this vulnerability is CVE-2018-14667. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.