CVE-2019-17091
published 2019-10-02CVE-2019-17091: faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20…
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
2.47%
82.7th percentile
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
Affected
41 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mojarra | — | — |
| eclipse | mojarra | >= 2.3.0 < 2.3.10 | 2.3.10 |
| oracle | application_testing_suite | — | — |
| oracle | application_testing_suite | — | — |
| oracle | banking_enterprise_product_manufacturing | — | — |
| oracle | banking_enterprise_product_manufacturing | — | — |
| oracle | communications_diameter_signaling_router | 8.0.0.0 – 8.4.0.5 | — |
| oracle | communications_network_integrity | — | — |
| oracle | communications_network_integrity | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | enterprise_data_quality | — | — |
| oracle | health_sciences_information_manager | — | — |
| oracle | healthcare_data_repository | — | — |
| oracle | mojarra_javaserver_faces | >= 2.2.0 < 2.2.20 | 2.2.20 |
| oracle | primavera_p6_enterprise_project_portfolio_management | — | — |
| oracle | primavera_p6_enterprise_project_portfolio_management | 15.1.0.0 – 15.2.18.7 | — |
| oracle | primavera_p6_enterprise_project_portfolio_management | 16.1.0.0 – 16.2.19.0 | — |
| oracle | primavera_p6_enterprise_project_portfolio_management | 17.1.0.0 – 17.12.15.0 | — |
| oracle | primavera_p6_enterprise_project_portfolio_management | 18.1.0.0 – 18.8.15.0 | — |
| oracle | rapid_planning | — | — |
| oracle | rapid_planning | — | — |
| oracle | retail_advanced_inventory_planning | — | — |
| oracle | retail_advanced_inventory_planning | — | — |
| oracle | retail_assortment_planning | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
vendor_debian6.1LOW
vendor_oracle6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Eclipse Mojarra) — CVE-2019-17091
vendor_oracle·2021-01-15·CVSS 6.1
CVE-2019-17091 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: General (Eclipse Mojarra) — CVE-2019-17091
Oracle Oracle Fusion Middleware Risk Matrix: General (Eclipse Mojarra) vulnerability
CVE: CVE-2019-17091
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Eclipse Mojarra) — CVE-2019-17091
vendor_oracle·2020-10-15·CVSS 6.1
CVE-2019-17091 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (Eclipse Mojarra) — CVE-2019-17091
Oracle Oracle Communications Risk Matrix: Platform (Eclipse Mojarra) vulnerability
CVE: CVE-2019-17091
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2020 (OCT 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Eclipse Mojarra) — CVE-2019-17091
vendor_oracle·2020-07-15·CVSS 6.1
CVE-2019-17091 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Core (Eclipse Mojarra) — CVE-2019-17091
Oracle Oracle Communications Applications Risk Matrix: Core (Eclipse Mojarra) vulnerability
CVE: CVE-2019-17091
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2020 (JUL 2020)
Oracle
Oracle Oracle Financial Services Applications Risk Matrix: Core (Eclipse Mojarra) — CVE-2019-17091
vendor_oracle·2020-04-15·CVSS 6.1
CVE-2019-17091 [MEDIUM] Oracle Oracle Financial Services Applications Risk Matrix: Core (Eclipse Mojarra) — CVE-2019-17091
Oracle Oracle Financial Services Applications Risk Matrix: Core (Eclipse Mojarra) vulnerability
CVE: CVE-2019-17091
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Maps (Mojarra) — CVE-2019-17091
vendor_oracle·2020-01-15·CVSS 6.1
CVE-2019-17091 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Maps (Mojarra) — CVE-2019-17091
Oracle Oracle Communications Applications Risk Matrix: Maps (Mojarra) vulnerability
CVE: CVE-2019-17091
CVSS: 6.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Debian
CVE-2019-17091: mojarra - faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra...
vendor_debian·2019·CVSS 6.1
CVE-2019-17091 [MEDIUM] CVE-2019-17091: mojarra - faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra...
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
Cross-site Scripting in Eclipse Mojarra
osv·2022-05-24
CVE-2019-17091 [MEDIUM] Cross-site Scripting in Eclipse Mojarra
Cross-site Scripting in Eclipse Mojarra
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces, allows Reflected XSS because a client window field is mishandled.
GHSA
Cross-site Scripting in Eclipse Mojarra
ghsa·2022-05-24
CVE-2019-17091 [MEDIUM] CWE-79 Cross-site Scripting in Eclipse Mojarra
Cross-site Scripting in Eclipse Mojarra
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces, allows Reflected XSS because a client window field is mishandled.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugs.eclipse.org/bugs/show_bug.cgi?id=548244https://github.com/eclipse-ee4j/mojarra/commit/8f70f2bd024f00ecd5b3dcca45df73edda29dceehttps://github.com/eclipse-ee4j/mojarra/commit/a3fa9573789ed5e867c43ea38374f4dbd5a8f81fhttps://github.com/eclipse-ee4j/mojarra/compare/2.3.9-RELEASE...2.3.10-RELEASEhttps://github.com/eclipse-ee4j/mojarra/files/3039198/advisory.txthttps://github.com/eclipse-ee4j/mojarra/issues/4556https://github.com/eclipse-ee4j/mojarra/pull/4567https://github.com/javaserverfaces/mojarra/commit/ae1c234d0a6750822ac69d4ae26d90e3571f27fehttps://github.com/javaserverfaces/mojarra/commit/f61935cd39f34329fbf27b1972a506fbdd0ab4d4https://github.com/javaserverfaces/mojarra/compare/2.2.19...2.2.20https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.htmlhttps://bugs.eclipse.org/bugs/show_bug.cgi?id=548244https://github.com/eclipse-ee4j/mojarra/commit/8f70f2bd024f00ecd5b3dcca45df73edda29dceehttps://github.com/eclipse-ee4j/mojarra/commit/a3fa9573789ed5e867c43ea38374f4dbd5a8f81fhttps://github.com/eclipse-ee4j/mojarra/compare/2.3.9-RELEASE...2.3.10-RELEASEhttps://github.com/eclipse-ee4j/mojarra/files/3039198/advisory.txthttps://github.com/eclipse-ee4j/mojarra/issues/4556https://github.com/eclipse-ee4j/mojarra/pull/4567https://github.com/javaserverfaces/mojarra/commit/ae1c234d0a6750822ac69d4ae26d90e3571f27fehttps://github.com/javaserverfaces/mojarra/commit/f61935cd39f34329fbf27b1972a506fbdd0ab4d4https://github.com/javaserverfaces/mojarra/compare/2.2.19...2.2.20https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/security-alerts/cpujan2020.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujul2020.htmlhttps://www.oracle.com/security-alerts/cpuoct2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
2019-10-02
Published