Логотип exploitDog
bind:CVE-2010-2057
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2010-2057

Количество 3

Количество 3

redhat логотип

CVE-2010-2057

больше 15 лет назад

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2057

больше 15 лет назад

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.

CVSS2: 5
EPSS: Низкий
github логотип

GHSA-4fv4-cq5v-x45m

больше 3 лет назад

Improper Authentication in Apache MyFaces

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2010-2057

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.

CVSS2: 4.3
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-2057

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.

CVSS2: 5
1%
Низкий
больше 15 лет назад
github логотип
GHSA-4fv4-cq5v-x45m

Improper Authentication in Apache MyFaces

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу