CVE-2019-17091 - CVE House
Back to Database
Status published Medium CVE-2019-17091

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse...

Vulnerability Description

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-17091

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

mojarra, mojarra javaserver faces, application testing suite, banking enterprise product manufacturing, communications diameter signaling router, communications network integrity, communications unified inventory management, enterprise data quality, health sciences information manager, healthcare data repository, primavera p6 enterprise project portfolio management, rapid planning, retail advanced inventory planning, retail assortment planning, retail bulk data integration, retail financial integration, retail integration bus, retail invoice matching, retail merchandising system, retail service backbone, retail store inventory management, secure global desktop, time and labor
Vulnerable Versions:
2.3.0, 2.2.0, 13.2.0.1, 13.3.0.1, 2.7.0, 2.8.0, 8.0.0.0, 7.3.5, 7.3.6, 7.3.0, 7.4.0, 12.2.1.3.0, 3.0, 7.0, 15.1.0.0, 16.1.0.0, 17.1.0.0, 18.1.0.0, 19.12.0.0, 12.1, 12.2, 15.0, 16.0, 16.0.3, 16.0.3.0, 14.0.4, 14.1.3, 15.0.3, 5.4, 5.5, 12.2.6

Timeline

Official Publish: October 2nd, 2019
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.