← Back

CVE-2019-17091

nvd nist
Published: Oct 2, 2019Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

Affected (40)

1 product
Mojarra
22 products
Mojarra Javaserver Faces
Application Testing Suite
Communications Network Integrity
Enterprise Data Quality
Healthcare Data Repository
Rapid Planning
Retail Assortment Planning
Retail Bulk Data Integration
Retail Financial Integration
Retail Integration Bus
Retail Invoice Matching
Retail Merchandising System
Retail Service Backbone
Retail Store Inventory Management
Secure Global Desktop
Time And Labor
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
From 2.3.0 to 2.3.10
From 2.2.0 to 2.2.20
Configuration B
38 vulnerable
Vulnerable SoftwareAffected Versions
Oracle
Version 13.2.0.1
Version 13.3.0.1
Oracle
Version 2.7.0
Version 2.8.0
From 8.0.0.0 to 8.4.0.5
Oracle
Version 7.3.5
Version 7.3.6
Oracle
Version 7.3.0
Version 7.4.0
Version 12.2.1.3.0
Version 3.0
Version 7.0
Oracle
From 15.1.0.0 to 15.2.18.7
From 16.1.0.0 to 16.2.19.0
From 17.1.0.0 to 17.12.15.0
From 18.1.0.0 to 18.8.15.0
Version 19.12.0.0
Oracle
Version 12.1
Version 12.2
Oracle
Version 15.0
Version 16.0
Version 16.0.3
Version 16.0.3.0
Oracle
Version 15.0
Version 16.0
Oracle
Version 15.0
Version 16.0
Version 16.0
Version 16.0
Oracle
Version 15.0
Version 16.0
Oracle
Version 14.0.4
Version 14.1.3
Version 15.0.3
Version 16.0.3
Oracle
Version 5.4
Version 5.5
From 12.2.6 to 12.2.11

References (34)

Source: cve@mitre.org
ExploitIssue TrackingPatchVendor Advisory
Source: cve@mitre.org
Release NotesThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitIssue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.