VulnerabilityModified
CVE-2019-17091
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
MEDIUM 6.1EPSS 2.47%
Does this matter?
Lower severity and a low EPSS score (2.47%). Track it; it rarely justifies an emergency change on its own.
Description
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 2.47% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- eclipse/mojarra · oracle/mojarra javaserver faces · oracle/application testing suite · oracle/banking enterprise product manufacturing · oracle/communications diameter signaling router · oracle/communications network integrity · oracle/communications unified inventory management · oracle/enterprise data quality · oracle/health sciences information manager · oracle/healthcare data repository · oracle/primavera p6 enterprise project portfolio management · oracle/rapid planning · oracle/retail advanced inventory planning · oracle/retail assortment planning · oracle/retail bulk data integration · oracle/retail financial integration · oracle/retail integration bus · oracle/retail invoice matching · oracle/retail merchandising system · oracle/retail service backbone · +3 more
- Source
- cve@mitre.org
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=548244Exploit, Issue Tracking, Patch, Vendor Advisory
- https://github.com/eclipse-ee4j/mojarra/commit/8f70f2bd024f00ecd5b3dcca45df73edda29dceePatch, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/commit/a3fa9573789ed5e867c43ea38374f4dbd5a8f81fPatch, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/compare/2.3.9-RELEASE...2.3.10-RELEASERelease Notes, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/files/3039198/advisory.txtExploit, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/issues/4556Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/pull/4567Patch, Third Party Advisory
- https://github.com/javaserverfaces/mojarra/commit/ae1c234d0a6750822ac69d4ae26d90e3571f27fePatch, Third Party Advisory
- https://github.com/javaserverfaces/mojarra/commit/f61935cd39f34329fbf27b1972a506fbdd0ab4d4Patch, Third Party Advisory
- https://github.com/javaserverfaces/mojarra/compare/2.2.19...2.2.20Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlPatch, Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=548244Exploit, Issue Tracking, Patch, Vendor Advisory
- https://github.com/eclipse-ee4j/mojarra/commit/8f70f2bd024f00ecd5b3dcca45df73edda29dceePatch, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/commit/a3fa9573789ed5e867c43ea38374f4dbd5a8f81fPatch, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/compare/2.3.9-RELEASE...2.3.10-RELEASERelease Notes, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/files/3039198/advisory.txtExploit, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/issues/4556Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/pull/4567Patch, Third Party Advisory
- https://github.com/javaserverfaces/mojarra/commit/ae1c234d0a6750822ac69d4ae26d90e3571f27fePatch, Third Party Advisory
- https://github.com/javaserverfaces/mojarra/commit/f61935cd39f34329fbf27b1972a506fbdd0ab4d4Patch, Third Party Advisory
- https://github.com/javaserverfaces/mojarra/compare/2.2.19...2.2.20Patch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.