LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-1000486: Primetek Primefaces Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2022
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-1000486 to its Known Exploited Vulnerabilities catalog on Jan 10, 2022, with a federal patch deadline of Jul 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Primetek Primefaces is vulnerable to a weak encryption flaw resulting in remote code execution

CVE-2017-1000486 is a remote code execution vulnerability in Primetek Primefaces applications that stems from weak encryption. An attacker who can abuse the flawed cryptography may execute code on the affected system. This matters because Primefaces is commonly embedded in Java web applications that handle business logic and data; successful exploitation can give an unauthenticated or low-privilege attacker a foothold on the application server. Confirm all product and version details against the vendor advisory before acting.

How it works

The weakness is classified as CWE-326 (Inadequate Encryption Strength). In plain terms, the product relies on encryption that is too weak to protect sensitive operations or parameters. When encryption that guards critical functionality can be broken or bypassed, an attacker can craft input that the application treats as legitimate, ultimately leading to remote code execution. Public detail on the exact cryptographic primitive, key handling, or request format is limited; defenders should treat any exposed Primefaces endpoint that processes encrypted or signed parameters as in scope and verify the precise attack surface in the vendor advisory. No assumption should be made about authentication requirements or preconditions beyond what the advisory states.

Am I affected? How to find it in your systems

Primefaces is a UI component suite typically used inside Java EE or Jakarta EE web applications, often running on application servers such as those hosting enterprise portals, internal tools, or customer-facing sites. Inventory steps include:

If you cannot confirm the exact component version, assume the application is in scope until proven otherwise by the vendor’s fixed-version list.

How to remediate

Patch first. Apply the updates supplied by the vendor exactly as described in the official advisory for CVE-2017-1000486. CISA’s required action is to apply updates per vendor instructions; follow that guidance and verify the installed version after deployment.

After patching, harden the broader class of weakness:

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls:

These measures do not eliminate the vulnerability; they only lower likelihood and impact until the patch is applied.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities can lead to full compromise of the host and subsequent data theft or ransomware deployment; ransomware use specifically tied to this CVE is not documented. If you have reason to believe an affected system was reached, follow your incident-response plan: isolate, preserve evidence, rotate credentials, and assess data access. As a simple additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts appear in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPrimetek · Primefaces Application
WeaknessCWE-326
Added to CISA KEVJan 10, 2022
Federal patch deadlineJul 10, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities