CVE-2018-14667 is a vulnerability in the RichFaces Framework 3.x through 3.3.4, specifically in the UserResource resource. The flaw allows remote, unauthenticated attackers to perform Expression Language (EL) injection, which can be chained with insecure Java deserialization via org.ajax4jsf.resource.UserResource$UriData. By sending a crafted serialized object, an attacker can trigger the deserialization process and execute arbitrary code on the server. The vulnerability leverages Java serialization magic methods and can be exploited using gadget chains, including JNDI RMI/LDAP injection, to achieve remote code execution (RCE).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository is a functional Java proof-of-concept lab for CVE-2018-14667, a RichFaces Java-deserialization issue enabling server-side expression-language evaluation and command execution. Dockerfile builds an intentionally obsolete Debian 9/JDK 6u45/JBoss 5.1.0.GA environment and deploys the RichFaces Photo Album 3.3.4.Final EAR on port 8080. The Maven project provides the older RichFaces, Seam, JBoss EL, Facelets, and JSF classes needed to construct a compatible serialized object graph. runner.bash compiles the project and executes Main. Main does not connect to a target; instead, it reflectively populates UserResource.UriData fields with StateHolderSaver-wrapped TagMethodExpression and TagValueExpression objects, Java-serializes the object, deflates it, URL64-encodes it, and prints a malicious .jsf resource URL. The embedded EL invokes Runtime.exec with a hard-coded touch /tmp/aaaaa command, making this an operational but basic payload generator rather than a scanner or automated delivery tool. README documents the vulnerable lab prerequisites and manual process, including visiting the Photo Album page before using the generated payload URL.
This six-file repository is a self-contained CVE-2018-14667 exploitation lab. Its Dockerfile constructs an obsolete Debian 9/JDK 6/JBoss 5.1 environment and deploys the RichFaces 3.3.4.Final Photo Album example application on port 8080. The Maven project under exploit/ supplies legacy RichFaces, JSF, Facelets, JBoss EL, and Seam dependencies needed to construct a compatible serialized gadget payload. runner.bash compiles the Java generator and runs Main. Main.java does not scan targets or issue network requests. Instead, it builds a serialized org.ajax4jsf.resource.UserResource.UriData object using reflection to populate createContent, modified, and expires fields with nested JSF/Facelets/JBoss EL expression objects. The expressions invoke Runtime.exec through the current request class loader. The object is Java-serialized, DEFLATE-compressed, URL64-encoded, and emitted as a /DATA/...jsf resource URL suitable for manual delivery to a target. The built-in command is touch /tmp/aaaaa, demonstrating server-side arbitrary command execution. The payload is basic and manually configurable, so it is operational rather than framework-weaponized.
This repository provides a working proof-of-concept exploit for CVE-2018-14667, a critical unauthenticated remote code execution vulnerability in JBoss RichFaces 3.x. The main exploit logic is implemented in Main.java, which generates a serialized Java payload that, when delivered to a vulnerable RichFaces endpoint, results in arbitrary command execution on the server. The README.md offers detailed background, setup instructions for a vulnerable environment, payload generation steps, and exploitation guidance. The exploit targets Java web applications using RichFaces 3.x, typically running on JBoss servers. The attack vector is network-based, requiring the attacker to send a crafted serialized object to a specific HTTP endpoint (e.g., /photoalbum/a4j/s/.../DATA/<payload>.jsf). The provided payload demonstrates code execution by creating a file at /tmp/PoorRichFaces on the target. The repository is structured with a single Java file for payload generation, a comprehensive README, and an image directory. No detection or patching scripts are included; the focus is on exploitation and demonstration of the vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.