CVE-2019-17091: XSS
Published Oct 2, 2019
·Updated
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
Affected Software
40 affected components
Eclipse Mojarra>=2.3.0<2.3.10
Oracle Mojarra Javaserver Faces>=2.2.0<2.2.20
Oracle Application Testing Suite=13.2.0.1
Oracle Application Testing Suite=13.3.0.1
Oracle Banking Enterprise Product Manufacturing=2.7.0
Oracle Banking Enterprise Product Manufacturing=2.8.0
Oracle Communications Diameter Signaling Router>=8.0.0.0<=8.4.0.5
Oracle Communications Network Integrity=7.3.5
Oracle Communications Network Integrity=7.3.6
Oracle Communications Unified Inventory Management=7.3.0
Oracle Communications Unified Inventory Management=7.4.0
Oracle Enterprise Data Quality=12.2.1.3.0
Oracle Health Sciences Information Manager=3.0
Oracle Healthcare Data Repository=7.0
Oracle Primavera P6 Enterprise Project Portfolio Management>=15.1.0.0<=15.2.18.7
Oracle Primavera P6 Enterprise Project Portfolio Management>=16.1.0.0<=16.2.19.0
Oracle Primavera P6 Enterprise Project Portfolio Management>=17.1.0.0<=17.12.15.0
Oracle Primavera P6 Enterprise Project Portfolio Management>=18.1.0.0<=18.8.15.0
Oracle Primavera P6 Enterprise Project Portfolio Management=19.12.0.0
Oracle Rapid Planning=12.1
Oracle Rapid Planning=12.2
Oracle Retail Advanced Inventory Planning=15.0
Oracle Retail Advanced Inventory Planning=16.0
Oracle Retail Assortment Planning=16.0.3
Oracle Retail Bulk Data Integration=16.0.3.0
Oracle Retail Financial Integration=15.0
Oracle Retail Financial Integration=16.0
Oracle Retail Integration Bus=15.0
Oracle Retail Integration Bus=16.0
Oracle Retail Invoice Matching=16.0
Oracle Retail Merchandising System=16.0
Oracle Retail Service Backbone=15.0
Oracle Retail Service Backbone=16.0
Oracle Retail Store Inventory Management=14.0.4
Oracle Retail Store Inventory Management=14.1.3
Oracle Retail Store Inventory Management=15.0.3
Oracle Retail Store Inventory Management=16.0.3
Oracle Secure Global Desktop=5.4
Oracle Secure Global Desktop=5.5
Oracle Time and Labor>=12.2.6<=12.2.11
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Oct 2, 2019
CVE Published
via MITRE·01:58 PM
Data Sourced
via MITRE·01:58 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2019-17091.
2
What is the severity level of CVE-2019-17091?
The severity level of CVE-2019-17091 is medium.
3
What software is affected by CVE-2019-17091?
Eclipse Mojarra, Mojarra for Eclipse EE4J before 2.3.10, and Mojarra JavaServer Faces before 2.2.20 are affected by CVE-2019-17091.
4
What is the impact of CVE-2019-17091?
CVE-2019-17091 allows for Reflected XSS (Cross-Site Scripting) attacks.
5
Where can I find more information about CVE-2019-17091?
More information about CVE-2019-17091 can be found at the following references: [1] [2] [3].