CVE-2012-2672
Last modified
CVE-2012-2672 is a vulnerability of currently unknown severity. Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | Mojarra | 2.1.7 |
References
- http://secunia.com/advisories/49284Vendor Advisory
- http://secunia.com/advisories/49284Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-2672?
How severe is CVE-2012-2672?
How do I fix CVE-2012-2672?
Are you affected by CVE-2012-2672?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
