Vulnerability Description
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Myfaces Trinidad | >= 1.0.0, < 1.0.13 |
Related Weaknesses (CWE)
References
- http://mail-archives.apache.org/mod_mbox/myfaces-users/201609.mbox/%3CCAM1yOjYM%Mailing ListVendor Advisory
- http://packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Third Party AdvisoryVDB Entry
- http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlPatch
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlPatch
- http://www.securityfocus.com/bid/93236Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1037633Third Party AdvisoryVDB Entry
- https://issues.apache.org/jira/browse/TRINIDAD-2542Vendor Advisory
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- http://mail-archives.apache.org/mod_mbox/myfaces-users/201609.mbox/%3CCAM1yOjYM%Mailing ListVendor Advisory
- http://packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Third Party AdvisoryVDB Entry
FAQ
What is CVE-2016-5019?
CVE-2016-5019 is a vulnerability with a CVSS score of 9.8 (CRITICAL). CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a...
How severe is CVE-2016-5019?
CVE-2016-5019 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-5019?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Myfaces Trinidad.