First published: Wed Oct 02 2019(Updated: )
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Mojarra | >=2.3.0<2.3.10 | |
Oracle Mojarra Javaserver Faces | >=2.2.0<2.2.20 | |
Oracle Application Testing Suite | =13.2.0.1 | |
Oracle Application Testing Suite | =13.3.0.1 | |
Oracle Banking Enterprise Product Manufacturing | =2.7.0 | |
Oracle Banking Enterprise Product Manufacturing | =2.8.0 | |
Oracle Communications Diameter Signaling Router | >=8.0.0.0<=8.4.0.5 | |
Oracle Communications Network Integrity | =7.3.5 | |
Oracle Communications Network Integrity | =7.3.6 | |
Oracle Communications Unified Inventory Management | =7.3.0 | |
Oracle Communications Unified Inventory Management | =7.4.0 | |
Oracle Enterprise Data Quality | =12.2.1.3.0 | |
Oracle Health Sciences Information Manager | =3.0 | |
Oracle Healthcare Data Repository | =7.0 | |
Oracle Primavera P6 Enterprise Project Portfolio Management | >=15.1.0.0<=15.2.18.7 | |
Oracle Primavera P6 Enterprise Project Portfolio Management | >=16.1.0.0<=16.2.19.0 | |
Oracle Primavera P6 Enterprise Project Portfolio Management | >=17.1.0.0<=17.12.15.0 | |
Oracle Primavera P6 Enterprise Project Portfolio Management | >=18.1.0.0<=18.8.15.0 | |
Oracle Primavera P6 Enterprise Project Portfolio Management | =19.12.0.0 | |
Oracle Rapid Planning | =12.1 | |
Oracle Rapid Planning | =12.2 | |
Oracle Retail Advanced Inventory Planning | =15.0 | |
Oracle Retail Advanced Inventory Planning | =16.0 | |
Oracle Retail Assortment Planning | =16.0.3 | |
Oracle Retail Bulk Data Integration | =16.0.3.0 | |
Oracle Retail Financial Integration | =15.0 | |
Oracle Retail Financial Integration | =16.0 | |
Oracle Retail Integration Bus | =15.0 | |
Oracle Retail Integration Bus | =16.0 | |
Oracle Retail Invoice Matching | =16.0 | |
Oracle Retail Merchandising System | =16.0 | |
Oracle Retail Service Backbone | =15.0 | |
Oracle Retail Service Backbone | =16.0 | |
Oracle Retail Store Inventory Management | =14.0.4 | |
Oracle Retail Store Inventory Management | =14.1.3 | |
Oracle Retail Store Inventory Management | =15.0.3 | |
Oracle Retail Store Inventory Management | =16.0.3 | |
Oracle Secure Global Desktop | =5.4 | |
Oracle Secure Global Desktop | =5.5 | |
Oracle Time and Labor | >=12.2.6<=12.2.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue is CVE-2019-17091.
The severity level of CVE-2019-17091 is medium.
Eclipse Mojarra, Mojarra for Eclipse EE4J before 2.3.10, and Mojarra JavaServer Faces before 2.2.20 are affected by CVE-2019-17091.
CVE-2019-17091 allows for Reflected XSS (Cross-Site Scripting) attacks.
More information about CVE-2019-17091 can be found at the following references: [1] [2] [3].