CVE-2019-17091
02.10.2019, 14:15
faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.
Vendor | Product | Version |
---|---|---|
eclipse | mojarra | 2.3.0 ≤ 𝑥 < 2.3.10 |
oracle | mojarra_javaserver_faces | 2.2.0 ≤ 𝑥 < 2.2.20 |
oracle | application_testing_suite | 13.2.0.1 |
oracle | application_testing_suite | 13.3.0.1 |
oracle | banking_enterprise_product_manufacturing | 2.7.0 |
oracle | banking_enterprise_product_manufacturing | 2.8.0 |
oracle | communications_diameter_signaling_router | 8.0.0.0 ≤ 𝑥 ≤ 8.4.0.5 |
oracle | communications_network_integrity | 7.3.5 |
oracle | communications_network_integrity | 7.3.6 |
oracle | communications_unified_inventory_management | 7.3.0 |
oracle | communications_unified_inventory_management | 7.4.0 |
oracle | enterprise_data_quality | 12.2.1.3.0 |
oracle | health_sciences_information_manager | 3.0 |
oracle | healthcare_data_repository | 7.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 15.1.0.0 ≤ 𝑥 ≤ 15.2.18.7 |
oracle | primavera_p6_enterprise_project_portfolio_management | 16.1.0.0 ≤ 𝑥 ≤ 16.2.19.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 17.1.0.0 ≤ 𝑥 ≤ 17.12.15.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 18.1.0.0 ≤ 𝑥 ≤ 18.8.15.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 19.12.0.0 |
oracle | rapid_planning | 12.1 |
oracle | rapid_planning | 12.2 |
oracle | retail_advanced_inventory_planning | 15.0 |
oracle | retail_advanced_inventory_planning | 16.0 |
oracle | retail_assortment_planning | 16.0.3 |
oracle | retail_bulk_data_integration | 16.0.3.0 |
oracle | retail_financial_integration | 15.0 |
oracle | retail_financial_integration | 16.0 |
oracle | retail_integration_bus | 15.0 |
oracle | retail_integration_bus | 16.0 |
oracle | retail_invoice_matching | 16.0 |
oracle | retail_merchandising_system | 16.0 |
oracle | retail_service_backbone | 15.0 |
oracle | retail_service_backbone | 16.0 |
oracle | retail_store_inventory_management | 14.0.4 |
oracle | retail_store_inventory_management | 14.1.3 |
oracle | retail_store_inventory_management | 15.0.3 |
oracle | retail_store_inventory_management | 16.0.3 |
oracle | secure_global_desktop | 5.4 |
oracle | secure_global_desktop | 5.5 |
oracle | time_and_labor | 12.2.6 ≤ 𝑥 ≤ 12.2.11 |
𝑥
= Vulnerable software versions

Debian Releases
References