Описание
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
It was found that Mojarra JavaServer Faces did not properly escape user-supplied content in certain circumstances. Contents of outputText tags and raw EL expressions that immediately follow script or style elements were not escaped. A remote attacker could use a specially crafted URL to execute arbitrary web script in the user's browser.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat BPM Suite 6 | JSF | Affected | ||
| Red Hat JBoss BRMS 5 | JSF | Will not fix | ||
| Red Hat JBoss BRMS 6 | JSF | Affected | ||
| Red Hat JBoss Data Grid 6 | JSF | Not affected | ||
| Red Hat JBoss Data Virtualization 6 | JSF | Affected | ||
| Red Hat JBoss Enterprise Application Platform 5 | JSF | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 6 | JSF | Affected | ||
| Red Hat JBoss Enterprise Web Server 1 | eap-4 | Will not fix | ||
| Red Hat JBoss Enterprise Web Server 1 | JSF | Will not fix | ||
| Red Hat JBoss Fuse Service Works 6 | JSF | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not per ...
Improper Neutralization of Input During Web Page Generation in Mojarra
Уязвимость программного обеспечения WebLogic Server, позволяющая удаленному злоумышленнику нарушить защищаемой информации
EPSS
4.3 Medium
CVSS2