CVE-2010-2057

Severity
5.0MEDIUM
EPSS
1.0%
top 22.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 20
Latest updateMay 17

Description

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

Mavenorg.apache.myfaces.core:myfaces-impl1.1.01.1.8+2
NVDapache/myfaces16 versions+15

Patches

🔴Vulnerability Details

3
GHSA
Improper Authentication in Apache MyFaces2022-05-17
OSV
Improper Authentication in Apache MyFaces2022-05-17
CVEList
CVE-2010-2057: shared/util/StateUtils2010-10-20

💬Community

1
Bugzilla
CVE-2010-2057 Apache MyFaces: encrypted view state does not include MAC2010-08-12
CVE-2010-2057 (MEDIUM CVSS 5) | shared/util/StateUtils.java in Apac | cvebase.io