Описание
Improper Authentication in Apache MyFaces
shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.
Пакеты
org.apache.myfaces.shared:myfaces-shared-core
>= 1.1.0, < 1.1.8
1.1.8
org.apache.myfaces.shared:myfaces-shared-core
>= 1.2.0, < 1.2.9
1.2.9
org.apache.myfaces.shared:myfaces-shared-core
>= 2.0.0, < 2.0.1
2.0.1
org.apache.myfaces.core:myfaces-impl
>= 1.1.0, < 1.1.8
1.1.8
org.apache.myfaces.core:myfaces-impl
>= 1.2.0, < 1.2.9
1.2.9
org.apache.myfaces.core:myfaces-impl
>= 2.0.0, < 2.0.1
2.0.1
Связанные уязвимости
shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.
shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.