Executive brief
Primetek Primefaces 5.x and other versions are vulnerable to a weak encryption flaw in the communication between the client and server. This vulnerability allows unauthenticated remote attackers to execute arbitrary code on the server.
Affected products
- Primetek Primefaces 4.0 to 4.0.24, 5.0 to 5.2.21, 5.3 to 5.3.8
Timeline
- 2016-02: disclosed: Initial public discussion of RCE in related components (Oracle NetBeans) using Primefaces.
- 2018-01-17: other: Initial analysis by NIST.
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.