Junglewise Threat Intelligence

CVE-2017-1000486: Inadequate Encryption Strength

CVE-2017-1000486 · Severity: critical · CVSS 3 · Exploited in the wild · Published 2021-06-03

Vendors: Maven.

Executive brief

Primetek Primefaces 5.x and other versions are vulnerable to a weak encryption flaw in the communication between the client and server. This vulnerability allows unauthenticated remote attackers to execute arbitrary code on the server.

Affected products

  • Primetek Primefaces 4.0 to 4.0.24, 5.0 to 5.2.21, 5.3 to 5.3.8

Timeline

  • 2016-02: disclosed: Initial public discussion of RCE in related components (Oracle NetBeans) using Primefaces.
  • 2018-01-17: other: Initial analysis by NIST.
  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.

Related threats