Vulnerability CVE-2012-2672


Published: 2012-06-16   Modified: 2012-06-17

Description:
Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Oracle -> Mojarra 

 References:
https://issues.jboss.org/browse/JBPAPP-9197
http://xforce.iss.net/xforce/xfdb/76179
http://www.openwall.com/lists/oss-security/2012/06/07/3
http://www.openwall.com/lists/oss-security/2012/06/07/2
http://secunia.com/advisories/51607
http://secunia.com/advisories/49284
http://rhn.redhat.com/errata/RHSA-2012-1594.html
http://rhn.redhat.com/errata/RHSA-2012-1592.html
http://rhn.redhat.com/errata/RHSA-2012-1591.html
http://java.net/jira/browse/JAVASERVERFACES-2436

Copyright 2024, cxsecurity.com

 

Back to Top