Loading
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.
Use CWE-917, Redhat vendor hub and Richfaces product page to widen CVE-2018-12532 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-14667, CVE-2018-12533 and CVE-2013-2165 for nearby disclosures in the same product family.