QID 997272
Date Published: 2024-02-20
QID 997272: Java (Maven) Security Update for org.apache.myfaces.core:myfaces-core-module (GHSA-92cv-wv2c-8899)
Apache MyFaces 1.1.7 and 1.2.8 (All previous versions are likely vulnerable), as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-92cv-wv2c-8899 for updates and patch information.
Vendor References
- GHSA-92cv-wv2c-8899 -
github.com/advisories/GHSA-92cv-wv2c-8899
CVEs related to QID 997272
Software Advisories
| Advisory ID | Software | Component | Link |
|---|