IssueDescription: It was found that RichFaces accepted arbitrary strings included in a URL and returned them unencoded in a CSS file. A remote attacker could use this flaw to perform cross-site scripting (XSS) attacks against a user running a RichFaces application.
This issue has been addressed in the following products: JBoss Portal 6.1.1 Via RHSA-2014:1973 https://rhn.redhat.com/errata/RHSA-2014-1973.html