Описание
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
| Релиз | Статус | Примечание |
|---|---|---|
| artful | ignored | end of life |
| bionic | not-affected | 2.2.8-5 |
| cosmic | ignored | end of life |
| devel | not-affected | 2.2.8-6 |
| disco | not-affected | 2.2.8-6 |
| esm-apps/bionic | not-affected | 2.2.8-5 |
| esm-apps/xenial | not-affected | 2.2.8-2 |
| esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was needed] |
| lucid | DNE | |
| precise | ignored | end of life |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not per ...
Improper Neutralization of Input During Web Page Generation in Mojarra
Уязвимость программного обеспечения WebLogic Server, позволяющая удаленному злоумышленнику нарушить защищаемой информации
EPSS
4.3 Medium
CVSS2