CVE-2012-2672
Summary
| CVE | CVE-2012-2672 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-06-17 03:41:41 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function. |
Risk And Classification
Primary CVSS: v2.0 2.1 from [email protected]
AV:L/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Security Advisory SA49284 - Oracle Mojarra "FacesContext" Information Disclosure Vulnerability - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| oss-security - CVE request: Mojarra allows deployed web applications to read FacesContext from other applications | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| oss-security - Re: CVE request: Mojarra allows deployed web applications to read FacesContext from other applications | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Security Advisory SA51607 - Red Hat update for JBoss Enterprise Application Platform - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [#JAVASERVERFACES-2436] Security bug with FacesContext in application startup - Java.net JIRA | af854a3a-2127-422b-91ae-364da2661108 | java.net | Exploit |
| [JBPAPP6-896] FacesContext.getCurrentInstance returns external context from a different deployment during application startup - Red Hat Issue Tracker | af854a3a-2127-422b-91ae-364da2661108 | issues.jboss.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.