VDB

DEBIAN-CVE-2012-2672

DEBIAN-CVE-2012-2672 PUBLISHED CVSS 8.600000381469727 HIGH

Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.

Risk Scores

CVSS v4.0
8.600000381469727
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
Debianmojarra
Debian:13mojarra0, 0, 0
Debian:11mojarra0, 0, 0
Debian:14mojarra0, 0, 0
Debian:12mojarra0, 0, 0

Timeline

  • Jun 17, 2012 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›