PT-2012-4172 · Oracle · Oracle Mojarra

David Jorm

·

Publicado

2012-06-17

·

Atualizado

2017-08-29

·

CVE-2012-2672

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Mojarra version 2.1.7
Description The issue allows local users to obtain context information and access resources from another WAR file by calling the FacesContext.getCurrentInstance function, due to improper cleanup of the FacesContext reference during startup.
Recommendations For Oracle Mojarra version 2.1.7, consider restricting access to the FacesContext.getCurrentInstance function until a proper fix is available. As a temporary workaround, review and modify the application's startup process to ensure proper cleanup of the FacesContext reference.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2012-2672
RHSA-2012:1591
RHSA-2012:1592

Produtos afetados

Oracle Mojarra