Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mojarra | Jul 30, 2024 | Jul 17, 2014 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 18545123 for version 12.1.2.0.0.Apply the Patch Set Update (PSU) 18544245 for version 12.1.1.0.0. | Apr 3, 2018 | Jul 17, 2014 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Feb 7, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub