Loading
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.
Use CWE-917, Redhat vendor hub and Richfaces product page to widen CVE-2018-12533 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-14667, CVE-2018-12532 and CVE-2013-2165 for nearby disclosures in the same product family.