This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Oracle First view 2014-07-17
Product Mojarra Last view 2014-07-17
Version 2.2.4 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:oracle:mojarra

Activity : Overall

Related : CVE

  Date Alert Description
4.3 2014-07-17 CVE-2013-5855

Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.

CWE : Common Weakness Enumeration

%idName
100% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Nessus® Vulnerability Scanner

id Description
2016-11-15 Name: The remote Fedora host is missing a security update.
File: fedora_2016-d6c87eb4af.nasl - Type: ACT_GATHER_INFO
2014-07-18 Name: The remote web server is affected by multiple vulnerabilities.
File: glassfish_cpu_jul_2014.nasl - Type: ACT_GATHER_INFO