CVE-2010-4007

Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack, a related issue to CVE-2010-2057.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:mojarra:1.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.1_02:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_01:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_02:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_03:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_04:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_05:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_06:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_07:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_08:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_09:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_10:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_11:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_13:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:1.2_15:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mojarra:2.0.3:*:*:*:*:*:*:*

History

21 Nov 2024, 01:20

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=623799 - () https://bugzilla.redhat.com/show_bug.cgi?id=623799 -
References () https://issues.apache.org/jira/browse/MYFACES-2749 - () https://issues.apache.org/jira/browse/MYFACES-2749 -

Information

Published : 2010-10-20 18:00

Updated : 2024-11-21 01:20


NVD link : CVE-2010-4007

Mitre link : CVE-2010-4007

CVE.ORG link : CVE-2010-4007


JSON object : View

Products Affected

oracle

  • mojarra
CWE
CWE-310

Cryptographic Issues