CVE-2017-1000486
primetek primefaces
Published 3 Jan 2018 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 10 Jan 2022, with a remediation deadline of 10 Jul 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution
References
- blog.mindedsecurity.com/2016/02/rce-in-oracle-netbeans-opensource.html · Exploit, Third Party Advisory
- cryptosense.com/weak-encryption-flaw-in-primefaces/ · Broken Link, Third Party Advisory
- github.com/primefaces/primefaces/issues/1152 · Issue Tracking, Third Party Advisory
- www.exploit-db.com/exploits/43733/ · Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-1000486 · US Government Resource