VulnerabilityModified
CVE-2012-2672
Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.
LOW 2.1EPSS 0.55%
Does this matter?
Lower severity and a low EPSS score (0.55%). Track it; it rarely justifies an emergency change on its own.
Description
Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.55% probability · 44th percentile
- CISA KEV
- Not listed
- Affected
- oracle/mojarra
- Source
- secalert@redhat.com
References
- http://java.net/jira/browse/JAVASERVERFACES-2436Exploit
- http://rhn.redhat.com/errata/RHSA-2012-1591.html
- http://rhn.redhat.com/errata/RHSA-2012-1592.html
- http://rhn.redhat.com/errata/RHSA-2012-1594.html
- http://secunia.com/advisories/49284Vendor Advisory
- http://secunia.com/advisories/51607
- http://www.openwall.com/lists/oss-security/2012/06/07/2
- http://www.openwall.com/lists/oss-security/2012/06/07/3
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76179
- https://issues.jboss.org/browse/JBPAPP-9197
- http://java.net/jira/browse/JAVASERVERFACES-2436Exploit
- http://rhn.redhat.com/errata/RHSA-2012-1591.html
- http://rhn.redhat.com/errata/RHSA-2012-1592.html
- http://rhn.redhat.com/errata/RHSA-2012-1594.html
- http://secunia.com/advisories/49284Vendor Advisory
- http://secunia.com/advisories/51607
- http://www.openwall.com/lists/oss-security/2012/06/07/2
- http://www.openwall.com/lists/oss-security/2012/06/07/3
- https://exchange.xforce.ibmcloud.com/vulnerabilities/76179
- https://issues.jboss.org/browse/JBPAPP-9197
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.