{"api_version":"1","generated_at":"2026-07-23T04:00:30+00:00","cve":"CVE-2012-2672","urls":{"html":"https://cve.report/CVE-2012-2672","api":"https://cve.report/api/cve/CVE-2012-2672.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2012-2672","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2012-2672"},"summary":{"title":"CVE-2012-2672","description":"Oracle Mojarra 2.1.7 does not properly \"clean up\" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.","state":"PUBLISHED","assigner":"redhat","published_at":"2012-06-17 03:41:41","updated_at":"2026-04-29 01:13:23"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://rhn.redhat.com/errata/RHSA-2012-1591.html","name":"http://rhn.redhat.com/errata/RHSA-2012-1591.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-1594.html","name":"http://rhn.redhat.com/errata/RHSA-2012-1594.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/76179","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/76179","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/49284","name":"http://secunia.com/advisories/49284","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Security Advisory SA49284 - Oracle Mojarra &quot;FacesContext&quot; Information Disclosure Vulnerability - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2012/06/07/2","name":"http://www.openwall.com/lists/oss-security/2012/06/07/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - CVE request: Mojarra allows deployed web applications to read FacesContext from other applications","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2012/06/07/3","name":"http://www.openwall.com/lists/oss-security/2012/06/07/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"oss-security - Re: CVE request: Mojarra allows deployed web applications\n to read FacesContext from other applications","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/51607","name":"http://secunia.com/advisories/51607","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory SA51607 - Red Hat update for JBoss Enterprise Application Platform - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2012-1592.html","name":"http://rhn.redhat.com/errata/RHSA-2012-1592.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://java.net/jira/browse/JAVASERVERFACES-2436","name":"http://java.net/jira/browse/JAVASERVERFACES-2436","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"[#JAVASERVERFACES-2436] Security bug with FacesContext in application startup - Java.net JIRA","mime":"text/html","httpstatus":"503","archivestatus":"200"},{"url":"https://issues.jboss.org/browse/JBPAPP-9197","name":"https://issues.jboss.org/browse/JBPAPP-9197","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[JBPAPP6-896] FacesContext.getCurrentInstance returns external context from a different deployment during application startup - Red Hat Issue Tracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2012-2672","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2012-2672","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2012","cve_id":"2672","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oracle","cpe5":"mojarra","cpe6":"2.1.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T19:42:31.886Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://issues.jboss.org/browse/JBPAPP-9197"},{"name":"RHSA-2012:1594","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1594.html"},{"name":"mojarra-facescontext-info-disc(76179)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/76179"},{"name":"49284","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/49284"},{"name":"51607","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/51607"},{"name":"RHSA-2012:1592","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1592.html"},{"name":"RHSA-2012:1591","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1591.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://java.net/jira/browse/JAVASERVERFACES-2436"},{"name":"[oss-security] 20120606 CVE request: Mojarra allows deployed web applications to read FacesContext from other applications","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/06/07/2"},{"name":"[oss-security] 20120606 Re: CVE request: Mojarra allows deployed web applications to read FacesContext from other applications","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2012/06/07/3"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2012-05-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"Oracle Mojarra 2.1.7 does not properly \"clean up\" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-08-28T12:57:01.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"tags":["x_refsource_MISC"],"url":"https://issues.jboss.org/browse/JBPAPP-9197"},{"name":"RHSA-2012:1594","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1594.html"},{"name":"mojarra-facescontext-info-disc(76179)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/76179"},{"name":"49284","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/49284"},{"name":"51607","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/51607"},{"name":"RHSA-2012:1592","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1592.html"},{"name":"RHSA-2012:1591","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2012-1591.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://java.net/jira/browse/JAVASERVERFACES-2436"},{"name":"[oss-security] 20120606 CVE request: Mojarra allows deployed web applications to read FacesContext from other applications","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/06/07/2"},{"name":"[oss-security] 20120606 Re: CVE request: Mojarra allows deployed web applications to read FacesContext from other applications","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2012/06/07/3"}]}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2012-2672","datePublished":"2012-06-17T01:00:00.000Z","dateReserved":"2012-05-14T00:00:00.000Z","dateUpdated":"2024-08-06T19:42:31.886Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2012-06-17 03:41:41","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oracle:mojarra:2.1.7:*:*:*:*:*:*:*","matchCriteriaId":"C4FC9BF2-44D9-4514-950D-84E75E27C9BA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2012","CveId":"2672","Ordinal":"1","Title":"CVE-2012-2672","CVE":"CVE-2012-2672","Year":"2012"},"notes":[{"CveYear":"2012","CveId":"2672","Ordinal":"1","NoteData":"Oracle Mojarra 2.1.7 does not properly \"clean up\" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.","Type":"Description","Title":"CVE-2012-2672"},{"CveYear":"2012","CveId":"2672","Ordinal":"2","NoteData":"2012-06-16","Type":"Other","Title":"Published"},{"CveYear":"2012","CveId":"2672","Ordinal":"3","NoteData":"2017-08-28","Type":"Other","Title":"Modified"}]}}}