5

CVE-2010-4007

Oracle Mojarra uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack, a related issue to CVE-2010-2057.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleMojarra Version1.1
OracleMojarra Version1.1_02
OracleMojarra Version1.2
OracleMojarra Version1.2_01
OracleMojarra Version1.2_02
OracleMojarra Version1.2_03
OracleMojarra Version1.2_04
OracleMojarra Version1.2_05
OracleMojarra Version1.2_06
OracleMojarra Version1.2_07
OracleMojarra Version1.2_08
OracleMojarra Version1.2_09
OracleMojarra Version1.2_10
OracleMojarra Version1.2_11
OracleMojarra Version1.2_12
OracleMojarra Version1.2_13
OracleMojarra Version1.2_14
OracleMojarra Version1.2_15
OracleMojarra Version2.0.0
OracleMojarra Version2.0.1
OracleMojarra Version2.0.2
OracleMojarra Version2.0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.33% 0.526
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N