PT-2012-4172 · Oracle · Oracle Mojarra
David Jorm
·
Publicado
2012-06-17
·
Atualizado
2017-08-29
·
CVE-2012-2672
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Mojarra version 2.1.7
Description
The issue allows local users to obtain context information and access resources from another WAR file by calling the
FacesContext.getCurrentInstance function, due to improper cleanup of the FacesContext reference during startup.Recommendations
For Oracle Mojarra version 2.1.7, consider restricting access to the
FacesContext.getCurrentInstance function until a proper fix is available. As a temporary workaround, review and modify the application's startup process to ensure proper cleanup of the FacesContext reference.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Oracle Mojarra