Impact
The vulnerability in Apache MyFaces allows an attacker to induce server‑side request forgery (SSRF) and local file inclusion (LFI) by supplying crafted input through the web interface. This flaw can let the attacker cause the application server to retrieve arbitrary URLs or read sensitive files on the host, potentially leading to privilege escalation or arbitrary code execution if the retrieved data is later executed. The weakness is a classic input validation failure, catalogued as CWE‑918.
Affected Systems
Apache MyFaces deployments from the Apache Software Foundation that are still running older unsupported releases are at risk. Versions not matching any of the patched releases (2.3.12, 2.3‑next‑M9, 3.0.4, 4.0.4, or 4.1.4) contain the flaw, while the listed releases resolve it. Any installation that has not applied one of those updates is potentially exploitable. Older unsupported releases may also be affected, so any third‑party or legacy MyFaces deployment should be reviewed.
Risk and Exploitability
The CVSS score of 9.8 assigns this vulnerability a critical severity level. However, the EPSS score of less than 1% indicates that exploit attempts are currently rare. The flaw has not been catalogued in the CISA KEV list. In practice, an attacker could trigger the SSRF or LFI by sending a specially crafted HTTP request to a vulnerable MyFaces endpoint, provided that the application accepts untrusted input for URL or file references. Once triggered, the effect can reach remote hosts on the internal network or expose local configuration files, giving the attacker high‑impact access.
OpenCVE Enrichment