CVE Feed

    Dashboard / CVE / CVE-2019-17091

    CVE-2019-17091

    faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

    Published:Oct 2, 2019
    Last Modified:Nov 21, 2024
    EPS:Oct 2, 2019
    EPSS Score:0.0842
    CVSS Score:6.1

    Affected Products

    Vendor
    Eclipse
    Product
    Mojarra
    Vendor
    Oracle
    Product
    Application Testing Suite
    Vendor
    Oracle
    Product
    Banking Enterprise Product Manufacturing
    Vendor
    Oracle
    Product
    Communications Diameter Signaling Router
    Vendor
    Oracle
    Product
    Communications Network Integrity
    Vendor
    Oracle
    Product
    Communications Unified Inventory Management
    Vendor
    Oracle
    Product
    Enterprise Data Quality
    Vendor
    Oracle
    Product
    Health Sciences Information Manager
    Vendor
    Oracle
    Product
    Healthcare Data Repository
    Vendor
    Oracle
    Product
    Mojarra Javaserver Faces
    Vendor
    Oracle
    Product
    Primavera P6 Enterprise Project Portfolio Management
    Vendor
    Oracle
    Product
    Rapid Planning
    Vendor
    Oracle
    Product
    Retail Advanced Inventory Planning
    Vendor
    Oracle
    Product
    Retail Assortment Planning
    Vendor
    Oracle
    Product
    Retail Bulk Data Integration
    Vendor
    Oracle
    Product
    Retail Financial Integration
    Vendor
    Oracle
    Product
    Retail Integration Bus
    Vendor
    Oracle
    Product
    Retail Invoice Matching
    Vendor
    Oracle
    Product
    Retail Merchandising System
    Vendor
    Oracle
    Product
    Retail Service Backbone
    Vendor
    Oracle
    Product
    Retail Store Inventory Management
    Vendor
    Oracle
    Product
    Secure Global Desktop
    Vendor
    Oracle
    Product
    Time And Labor

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High