← Back

CVE-2010-4007

nvd nist
Published: Oct 20, 2010Modified: Apr 29, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack, a related issue to CVE-2010-2057.

Affected (22)

Products: Oracle: Mojarra
1 product
Mojarra
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 1.1
Version 1.1_02
Version 1.2
Version 1.2_01
Version 1.2_02
Version 1.2_03
Version 1.2_04
Version 1.2_05
Version 1.2_06
Version 1.2_07
Version 1.2_08
Version 1.2_09
Version 1.2_10
Version 1.2_11
Version 1.2_12
Version 1.2_13
Version 1.2_14
Version 1.2_15
Version 2.0.0
Version 2.0.1
Version 2.0.2
Version 2.0.3

Related CWEs

References (4)

Timeline

No history available yet.