RichFaces version 4.5.3 ≤ 4.5.17 is vulnerable to injection of arbitrary EL variable mappers, allowing mitigation bypass of CVE-2015-0279 and thereby remote code execution. External Reference: https://codewhitesec.blogspot.com/2018/05/poor-richfaces.html
Upstream issue: https://issues.jboss.org/browse/RF-14309
Statement: This issue does not affect the following Red Hat products, as they do not include the vulnerable version of the RichFaces component: Red Hat JBoss EAP 5.2 Red Hat JBoss Data Virtualization 6.4 Red Hat JBoss BRMS 5.3 Red Hat JBoss Operations Network 3.3