vulnerability

Oracle WebLogic: CVE-2019-17091 : Critical Patch Update

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Oct 2, 2019
Added
Oct 17, 2019
Modified
Jan 16, 2020

Description

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

Solution

oracle-weblogic-oct-2019-cpu-12_2_1_3_0
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.