PT-2012-4172 · Oracle · Oracle Mojarra

David Jorm

·

Published

2012-06-17

·

Updated

2017-08-29

·

CVE-2012-2672

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Mojarra version 2.1.7
Description The issue allows local users to obtain context information and access resources from another WAR file by calling the FacesContext.getCurrentInstance function, due to improper cleanup of the FacesContext reference during startup.
Recommendations For Oracle Mojarra version 2.1.7, consider restricting access to the FacesContext.getCurrentInstance function until a proper fix is available. As a temporary workaround, review and modify the application's startup process to ensure proper cleanup of the FacesContext reference.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2012-2672
RHSA-2012:1591
RHSA-2012:1592

Affected Products

Oracle Mojarra