Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2013-5855

Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.

CVSS v2:

  • Severity: Low
  • Score: 4.3
  • AV:N/AC:M/Au:N/C:N/I:P/A:N
Software From Fixed in
oracle / mojarra 2.1.2 2.1.2.x
oracle / mojarra 2.2.2 2.2.2.x
oracle / mojarra 2.1.16 2.1.16.x
oracle / mojarra 2.1.13 2.1.13.x
oracle / mojarra 2.1.12 2.1.12.x
oracle / mojarra 2.1.3 2.1.3.x
oracle / mojarra 2.2.5 2.2.5.x
oracle / mojarra 2.1.10 2.1.10.x
oracle / mojarra 2.1.20 2.1.20.x
oracle / mojarra 2.1.4 2.1.4.x
oracle / mojarra 2.2.1 2.2.1.x
oracle / mojarra 2.2.3 2.2.3.x
oracle / mojarra 2.1.18 2.1.18.x
oracle / mojarra 2.2.0 2.2.0.x
oracle / mojarra 2.1.6 2.1.6.x
oracle / mojarra 2.1.22 2.1.22.x
oracle / mojarra 2.1.9 2.1.9.x
oracle / mojarra 2.1.15 2.1.15.x
oracle / mojarra 2.1.25 2.1.25.x
oracle / mojarra 2.1.7 2.1.7.x
oracle / mojarra 2.1.1 2.1.1.x
oracle / mojarra 2.1.23 2.1.23.x
oracle / mojarra 2.1.5 2.1.5.x
oracle / mojarra 2.1.11 2.1.11.x
oracle / mojarra 2.1.24 2.1.24.x
oracle / mojarra 2.1.8 2.1.8.x
oracle / mojarra 2.1.26 2.1.26.x
oracle / mojarra 2.1.17 2.1.17.x
oracle / mojarra 2.1.27 2.1.27.x
oracle / mojarra 2.1.14 2.1.14.x
oracle / mojarra 2.1.19 2.1.19.x
oracle / mojarra 2.1.21 2.1.21.x
oracle / mojarra 2.1.0 2.1.0.x
oracle / mojarra 2.2.4 2.2.4.x
org.glassfish / javax.faces 2.2.0 2.2.6
org.glassfish / javax.faces 2.1.0 2.1.28