PT-2014-1721 · Oracle · Oracle Mojarra+1

Publicado

2014-07-16

·

Atualizado

2022-05-14

·

CVE-2013-5855

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Oracle Mojarra versions 2.2.x through 2.2.5 Oracle Mojarra versions 2.1.x through 2.1.27
Description The issue arises from inadequate encoding when using a h:outputText tag or an EL expression after a script or style block, allowing remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors. This can be exploited by remote attackers to perform XSS attacks.
Recommendations For Oracle Mojarra versions 2.2.x through 2.2.5, update to version 2.2.6 or later. For Oracle Mojarra versions 2.1.x through 2.1.27, update to version 2.1.28 or later. As a temporary workaround, consider restricting the use of h:outputText tags and EL expressions after script or style blocks until a patch is available.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-00734
CVE-2013-5855
GHSA-3M3R-82GC-53MJ

Produtos afetados

Oracle Mojarra
Oracle Weblogic Server