MEDIUM✓ PATCH🇬🇧 English

CVE-2019-17091

CVSS 6.1v3.1pub. 2019-10-02upd. 2024-11-21

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • Eclipse Mojarra

    APP
    Eclipse
    2.3.0 – 2.3.10 (bez)
  • Oracle Application Testing Suite

    APP
    Oracle
    13.2.0.113.3.0.1
  • Oracle Banking Enterprise Product Manufacturing

    APP
    Oracle
    2.7.02.8.0
  • Oracle Communications Diameter Signaling Router

    APP
    Oracle
    8.0.0.0 – 8.4.0.5
  • Oracle Communications Network Integrity

    APP
    Oracle
    7.3.57.3.6
  • Oracle Communications Unified Inventory Management

    APP
    Oracle
    7.3.07.4.0
  • Oracle Enterprise Data Quality

    APP
    Oracle
    12.2.1.3.0
  • Oracle Healthcare Data Repository

    APP
    Oracle
    7.0
  • Oracle Health Sciences Information Manager

    APP
    Oracle
    3.0
  • Oracle Mojarra Javaserver Faces

    APP
    Oracle
    2.2.0 – 2.2.20 (bez)
  • Oracle Primavera P6 Enterprise Project Portfolio Management

    APP
    Oracle
    19.12.0.016.1.0.0 – 16.2.19.015.1.0.0 – 15.2.18.717.1.0.0 – 17.12.15.018.1.0.0 – 18.8.15.0
  • Oracle Rapid Planning

    APP
    Oracle
    12.112.2
  • Oracle Retail Advanced Inventory Planning

    APP
    Oracle
    15.016.0
  • Oracle Retail Assortment Planning

    APP
    Oracle
    16.0.3
  • Oracle Retail Bulk Data Integration

    APP
    Oracle
    16.0.3.0
  • Oracle Retail Financial Integration

    APP
    Oracle
    15.016.0
  • Oracle Retail Integration Bus

    APP
    Oracle
    15.016.0
  • Oracle Retail Invoice Matching

    APP
    Oracle
    16.0
  • Oracle Retail Merchandising System

    APP
    Oracle
    16.0
  • Oracle Retail Service Backbone

    APP
    Oracle
    15.016.0
  • Oracle Retail Store Inventory Management

    APP
    Oracle
    14.0.414.1.315.0.316.0.3
  • Oracle Secure Global Desktop

    APP
    Oracle
    5.45.5
  • Oracle Time And Labor

    APP
    Oracle
    12.2.6 – 12.2.11
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
XSS
CWE
Referencje

Powiązane podatności

CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓ten sam produkt

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2020-2555CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE przez deserializację w Oracle Coherence via protokół T3

CVE-2017-9841CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w PHPUnit — wykonanie kodu PHP przez eval-stdin.php

CVE-2026-70862CRITICAL9.1ten sam produkt

Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easil...