CVE-2010-2086

Severity
4.0MEDIUM
EPSS
2.9%
top 13.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 27
Latest updateMay 17

Description

Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.

CVSS vector

AV:N/AC:H/C:P/I:P/A:NExploitability: 4.9 | Impact: 4.9

Affected Packages2 packages

NVDapache/myfaces1.1.7, 1.2.8+1

🔴Vulnerability Details

3
GHSA
Apache MyFaces Cross-site Scripting vulnerability2022-05-17
OSV
Apache MyFaces Cross-site Scripting vulnerability2022-05-17
CVEList
CVE-2010-2086: Apache MyFaces 12010-05-27

💥Exploits & PoCs

3
Exploit-DB
phpBB - 'viewtopic.php' Arbitrary Code Execution (Metasploit)2010-07-03
Exploit-DB
Juniper SSL-VPN IVE - 'JuniperSetupDLL.dll' ActiveX Control Buffer Overflow (Metasploit)2010-05-09
Exploit-DB
Sambar Server 6 - Search Results Buffer Overflow (Metasploit)2010-02-13

📋Vendor Advisories

1
Red Hat
MyFaces: XSS via state view2010-02-08

💬Community

1
Bugzilla
CVE-2010-2086 MyFaces: XSS via state view2010-05-31
CVE-2010-2086 (MEDIUM CVSS 4) | Apache MyFaces 1.1.7 and 1.2.8 | cvebase.io