faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NEclipse Mojarra
APPEclipse2.3.0 – 2.3.10 (excl.)Oracle Application Testing Suite
APPOracle13.2.0.113.3.0.1Oracle Banking Enterprise Product Manufacturing
APPOracle2.7.02.8.0Oracle Communications Diameter Signaling Router
APPOracle8.0.0.0 – 8.4.0.5Oracle Communications Network Integrity
APPOracle7.3.57.3.6Oracle Communications Unified Inventory Management
APPOracle7.3.07.4.0Oracle Enterprise Data Quality
APPOracle12.2.1.3.0Oracle Healthcare Data Repository
APPOracle7.0Oracle Health Sciences Information Manager
APPOracle3.0Oracle Mojarra Javaserver Faces
APPOracle2.2.0 – 2.2.20 (excl.)Oracle Primavera P6 Enterprise Project Portfolio Management
APPOracle19.12.0.016.1.0.0 – 16.2.19.015.1.0.0 – 15.2.18.717.1.0.0 – 17.12.15.018.1.0.0 – 18.8.15.0Oracle Rapid Planning
APPOracle12.112.2Oracle Retail Advanced Inventory Planning
APPOracle15.016.0Oracle Retail Assortment Planning
APPOracle16.0.3Oracle Retail Bulk Data Integration
APPOracle16.0.3.0Oracle Retail Financial Integration
APPOracle15.016.0Oracle Retail Integration Bus
APPOracle15.016.0Oracle Retail Invoice Matching
APPOracle16.0Oracle Retail Merchandising System
APPOracle16.0Oracle Retail Service Backbone
APPOracle15.016.0Oracle Retail Store Inventory Management
APPOracle14.0.414.1.315.0.316.0.3Oracle Secure Global Desktop
APPOracle5.45.5Oracle Time And Labor
APPOracle12.2.6 – 12.2.11
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSS
CWE
References
Related vulnerabilities
CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓same product
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2020-2555CRITICAL9.8⚠ KEVPL ✓same product
RCE przez deserializację w Oracle Coherence via protokół T3
CVE-2017-9841CRITICAL9.8⚠ KEVPL ✓same product
RCE w PHPUnit — wykonanie kodu PHP przez eval-stdin.php
CVE-2026-70862CRITICAL9.1same product
Vulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easil...