CVE-2010-4007
20.10.2010, 18:00
Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack, a related issue to CVE-2010-2057.Enginsight
Vendor | Product | Version |
---|---|---|
oracle | mojarra | 1.1 |
oracle | mojarra | 1.1_02:_02 |
oracle | mojarra | 1.2 |
oracle | mojarra | 1.2_01:_01 |
oracle | mojarra | 1.2_02:_02 |
oracle | mojarra | 1.2_03:_03 |
oracle | mojarra | 1.2_04:_04 |
oracle | mojarra | 1.2_05:_05 |
oracle | mojarra | 1.2_06:_06 |
oracle | mojarra | 1.2_07:_07 |
oracle | mojarra | 1.2_08:_08 |
oracle | mojarra | 1.2_09:_09 |
oracle | mojarra | 1.2_10:_10 |
oracle | mojarra | 1.2_11:_11 |
oracle | mojarra | 1.2_12:_12 |
oracle | mojarra | 1.2_13:_13 |
oracle | mojarra | 1.2_14:_14 |
oracle | mojarra | 1.2_15:_15 |
oracle | mojarra | 2.0.0 |
oracle | mojarra | 2.0.1 |
oracle | mojarra | 2.0.2 |
oracle | mojarra | 2.0.3 |
𝑥
= Vulnerable software versions

Debian Releases
Common Weakness Enumeration