CISA added CVE-2018-14667, a vulnerability in the end-of-life JBoss RichFaces framework, to its Known Exploited Vulnerabilities (KEV) Catalog in September 2023. The listing indicates that the flaw was known to have been exploited, but public reporting did not describe the attacks or establish that a new campaign was underway. RichFaces had already reached end of life, so organizations still running it need to identify their specific deployments and consult current maintainer guidance rather than assume a supported patch exists.
What is CVE-2018-14667?
CVE-2018-14667 is a critical arbitrary-code-execution vulnerability associated with Red Hat JBoss RichFaces, a framework that supplied Ajax UI components for JavaServer Faces applications. The GitHub Advisory Database summarizes the issue as allowing a remote, unauthenticated attacker to execute arbitrary code by chaining Java serialized objects through org.ajax4jsf.resource.UserResource$UriData (GitHub Advisory Database).
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
JBoss in Action: Configuring the JBoss Application Server | $26.02 | Buy on Amazon |
| 2 |
|
JBoss: A Developer's Notebook | $14.00 | Buy on Amazon |
| 3 |
|
JBoss Administration and Development | $9.92 | Buy on Amazon |
| 4 |
|
JBoss Portal Server Development | $16.54 | Buy on Amazon |
| 5 |
|
JBoss at Work: A Practical Guide | $18.86 | Buy on Amazon |
That summary describes the vulnerability record; it does not establish that every RichFaces deployment or version is vulnerable. The available information does not provide a complete affected-version matrix, so administrators must identify the framework and version actually in use and verify applicability with the relevant vendor or application maintainer.
What CISA’s KEV addition means—and what it does not
CISA added CVE-2018-14667 to the KEV Catalog on September 28, 2023, according to SecurityWeek’s report published the following day. CISA describes KEV as an authoritative catalog of vulnerabilities known to have been exploited in the wild, with action and due-date fields for listed entries (CISA KEV Catalog; SecurityWeek, September 29, 2023).
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- New
- Mint Condition
- Dispatch same day for order received before 12 noon
- Guaranteed packaging
- No quibbles returns
The catalog entry is evidence of known exploitation, not a public incident report. SecurityWeek said no details about the attacks had been shared, leaving unresolved whether CISA had learned of ongoing activity or was recording earlier exploitation. The cited reporting does not verify current exploitation activity, identify victims, or provide an attack count.
RichFaces was already end of life
RichFaces is a legacy JBoss project, and SecurityWeek reported that it reached end of life in June 2016. End of life complicates remediation: organizations should not assume that a supported fix is available simply because the vulnerability is listed in KEV. The sources cited here do not establish a current fixed version or a safe workaround for a particular deployment.
Rank #2
- ISBN13: 9780596100070
- Condition: New
- Notes: BRAND NEW FROM PUBLISHER! 100% SatisfactionTracking provided on most orders. Buy with Confidence! Millions of books sold!
What the 2023 federal deadline required
SecurityWeek reported that U.S. federal agencies were required to mitigate the vulnerability or discontinue use of the product by October 19, 2023. That was a historical deadline for federal agencies—not a current deadline and not a universal legal requirement for every organization.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to assess a RichFaces deployment now
For organizations that may still depend on RichFaces, the useful first step is to establish what is actually deployed, then choose a risk treatment based on verified applicability and business impact.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
- Inventory the application. Check application dependencies, build files, packaged libraries, and deployment artifacts for RichFaces. Record the version and the applications that depend on it.
- Confirm applicability. Compare the identified component and version with current vendor or application-maintainer guidance. The available vulnerability summary does not supply a complete affected-version matrix.
- Check current remediation guidance. Review the live CISA KEV entry and consult the vendor or application owner for applicable instructions. CISA’s general guidance is to apply updates according to vendor instructions, but a current RichFaces patch target is not established in the cited sources.
- Decide how to treat an unsupported dependency. Depending on whether the deployment is affected, its exposure, its business impact, and the effort involved, the system owner may need to migrate, replace the dependency, or select another risk treatment. The cited information does not prescribe one option for every system.
CISA’s catalog is dynamic. Check its live record for current entry details rather than treating a 2023 report or deadline as an up-to-date operational instruction.
Quick Recap
Best Value
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

