CVE-2010-2057
20.10.2010, 18:00
shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.Enginsight
Vendor | Product | Version |
---|---|---|
apache | myfaces | 1.1.0 |
apache | myfaces | 1.1.1 |
apache | myfaces | 1.1.2 |
apache | myfaces | 1.1.3 |
apache | myfaces | 1.1.4 |
apache | myfaces | 1.1.5 |
apache | myfaces | 1.1.6 |
apache | myfaces | 1.1.7 |
apache | myfaces | 1.2.2 |
apache | myfaces | 1.2.3 |
apache | myfaces | 1.2.4 |
apache | myfaces | 1.2.5 |
apache | myfaces | 1.2.6 |
apache | myfaces | 1.2.7 |
apache | myfaces | 1.2.8 |
apache | myfaces | 2.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References