← Back

CVE-2010-2087

nvd nist
Published: May 27, 2010Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application Server, Caucho Resin, and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.

Affected (2)

Products: Oracle: Mojarra
1 product
Mojarra
Configuration A
2 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Oracle
Version 1.2_14
Version 2.0.2
Running on/withPlatform Versions
Caucho
Resin
All versions
Ibm
Websphere Application Server
All versions

Timeline

No history available yet.