CVE-2016-5019

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
References
Link Resource
http://mail-archives.apache.org/mod_mbox/myfaces-users/201609.mbox/%3CCAM1yOjYM%2BEW3mLUfX0pNAVLfUFRAw-Bhvkp3UE5%3DEQzR8Yxsfw%40mail.gmail.com%3E Mailing List Vendor Advisory
http://packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Disclosure.html Third Party Advisory VDB Entry
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html Patch
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html Patch
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Patch
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Patch
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html Patch
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Patch
http://www.securityfocus.com/bid/93236 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037633 Third Party Advisory VDB Entry
https://issues.apache.org/jira/browse/TRINIDAD-2542 Vendor Advisory
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
http://mail-archives.apache.org/mod_mbox/myfaces-users/201609.mbox/%3CCAM1yOjYM%2BEW3mLUfX0pNAVLfUFRAw-Bhvkp3UE5%3DEQzR8Yxsfw%40mail.gmail.com%3E Mailing List Vendor Advisory
http://packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Disclosure.html Third Party Advisory VDB Entry
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html Patch
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html Patch
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Patch
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html Patch
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html Patch
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Patch
http://www.securityfocus.com/bid/93236 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1037633 Third Party Advisory VDB Entry
https://issues.apache.org/jira/browse/TRINIDAD-2542 Vendor Advisory
https://www.oracle.com/security-alerts/cpujan2020.html
https://www.oracle.com/security-alerts/cpujul2020.html
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:53

Type Values Removed Values Added
References () http://mail-archives.apache.org/mod_mbox/myfaces-users/201609.mbox/%3CCAM1yOjYM%2BEW3mLUfX0pNAVLfUFRAw-Bhvkp3UE5%3DEQzR8Yxsfw%40mail.gmail.com%3E - Mailing List, Vendor Advisory () http://mail-archives.apache.org/mod_mbox/myfaces-users/201609.mbox/%3CCAM1yOjYM%2BEW3mLUfX0pNAVLfUFRAw-Bhvkp3UE5%3DEQzR8Yxsfw%40mail.gmail.com%3E - Mailing List, Vendor Advisory
References () http://packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Disclosure.html - Third Party Advisory, VDB Entry () http://packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Disclosure.html - Third Party Advisory, VDB Entry
References () http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html - Patch () http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html - Patch
References () http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html - Patch () http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html - Patch
References () http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html - Patch () http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html - Patch
References () http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html - Patch () http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html - Patch
References () http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html - Patch () http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html - Patch
References () http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html - Patch () http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html - Patch
References () http://www.securityfocus.com/bid/93236 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/93236 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1037633 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1037633 - Third Party Advisory, VDB Entry
References () https://issues.apache.org/jira/browse/TRINIDAD-2542 - Vendor Advisory () https://issues.apache.org/jira/browse/TRINIDAD-2542 - Vendor Advisory
References () https://www.oracle.com/security-alerts/cpujan2020.html - () https://www.oracle.com/security-alerts/cpujan2020.html -
References () https://www.oracle.com/security-alerts/cpujul2020.html - () https://www.oracle.com/security-alerts/cpujul2020.html -

Information

Published : 2016-10-03 18:59

Updated : 2024-11-21 02:53


NVD link : CVE-2016-5019

Mitre link : CVE-2016-5019

CVE.ORG link : CVE-2016-5019


JSON object : View

Products Affected

apache

  • myfaces_trinidad
CWE
CWE-502

Deserialization of Untrusted Data