CVE-2010-4007
20.10.2010, 18:00
Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack, a related issue to CVE-2010-2057.Enginsight
| Vendor | Product | Version |
|---|---|---|
| oracle | mojarra | 1.1 |
| oracle | mojarra | 1.1_02:_02 |
| oracle | mojarra | 1.2 |
| oracle | mojarra | 1.2_01:_01 |
| oracle | mojarra | 1.2_02:_02 |
| oracle | mojarra | 1.2_03:_03 |
| oracle | mojarra | 1.2_04:_04 |
| oracle | mojarra | 1.2_05:_05 |
| oracle | mojarra | 1.2_06:_06 |
| oracle | mojarra | 1.2_07:_07 |
| oracle | mojarra | 1.2_08:_08 |
| oracle | mojarra | 1.2_09:_09 |
| oracle | mojarra | 1.2_10:_10 |
| oracle | mojarra | 1.2_11:_11 |
| oracle | mojarra | 1.2_12:_12 |
| oracle | mojarra | 1.2_13:_13 |
| oracle | mojarra | 1.2_14:_14 |
| oracle | mojarra | 1.2_15:_15 |
| oracle | mojarra | 2.0.0 |
| oracle | mojarra | 2.0.1 |
| oracle | mojarra | 2.0.2 |
| oracle | mojarra | 2.0.3 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration