🛡️ CVE-2013-2165 — richfaces
Description
Remote code execution due to insecure deserialization
A flaw was found in the way JBoss RichFaces handled deserialization. A remote attacker could use this flaw to trigger the execution of the deserialization methods in any serializable class deployed on the server. This could lead to a variety of security impacts depending on the deserialization logic of these classes.
Affected software
CVE-2013-2165 is recorded against 1 package.
- org.richfaces:richfaces (from 4.0.0 up to 4.3.2)
Timeline and source
Published on 13 May 2022 and last revised on 8 November 2023. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
nvd.nist.gov (Advisory)
access.redhat.com (Web)
bugzilla.redhat.com (Web)
jvn.jp (Web)
jvndb.jvn.jp (Web)
packetstormsecurity.com (Web)
seclists.org (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| org.richfaces:richfaces | 4.0.0 | 4.3.2 |
References
Similar Threats
- Unknown CVE-2014-0086
- Critical CVE-2018-12532
- Critical CVE-2018-12533
- Critical CVE-2018-14667
More CVE 2013 advisories
Browse all of CVE 2013 in the advisory index.
Site Security Check
Is richfaces part of your stack?
CVE-2013-2165 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.