Overview
Oracle JavaServer Faces contains multiple vulnerabilities which could allow an attacker to obtain sensitive information.
Description
Oracle JavaServer Faces contains multiple vulnerabilities which could allow an attacker to obtain sensitive information. Alex Kouzemtchenko and Jon Passki of Coverity Security Research Labs vulnerability report states Oracle JavaServer Faces contains the following vulnerabilities:
For additional information see Oracle Critical Patch Update Advisory - October 2013. |
Impact
A remote unauthenticated attacker may obtain sensitive information. |
Solution
These vulnerabilities have been addressed in Oracle Critical Patch Update Advisory - October 2013. Affected users are advised to apply the recommended Critical Path updates listed in the Oracle Critical Patch Update Advisory - October 2013 for CVE-2013-3827. |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 5 | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Temporal | 4.1 | E:F/RL:OF/RC:C |
Environmental | 3.5 | CDP:L/TD:M/CR:ND/IR:ND/AR:ND |
References
- http://javaserverfaces.java.net/download.html
- http://docs.oracle.com/javaee/6/api/javax/faces/webapp/FacesServlet.html
- http://cwe.mitre.org/data/definitions/22.html
- http://cwe.mitre.org/data/definitions/367.html
- http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html
- http://security.coverity.com/advisory/2013/Oct/two-path-traversal-defects-in-oracles-jsf2-implementation.html
Acknowledgements
Thanks to Alex Kouzemtchenko and Jon Passki of Coverity Security Research Labs for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2013-3827 |
Date Public: | 2013-10-15 |
Date First Published: | 2013-10-18 |
Date Last Updated: | 2013-10-21 11:28 UTC |
Document Revision: | 17 |