ZeroHour

CVE-2019-17091

PoC ×2
CVSS 3.1
6.1 medium
EPSS
2%p84
Published
()
Modified
Description

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

Vendors
eclipseoracle
Products
mojarra, mojarra javaserver faces, application testing suite, banking enterprise product manufacturing, communications diameter signaling router, communications network integrity, communications unified inventory management, enterprise data quality, health sciences information manager, healthcare data repository, primavera p6 enterprise project portfolio management, rapid planning
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.