CVE-2016-5019
Apache MyFaces Trinidad Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
CoreResponseStateManager en Apache MyFaces Trinidad 1.0.0 hasta la versión 1.0.13, 1.2.x en versiones anteriores a 1.2.15, 2.0.x en versiones anteriores a 2.0.2 y 2.1.x en versiones anteriores a 2.1.2 podría permitir a atacantes llevar a cabo ataques de deserialización a través de una cadena de vista de estado serializada manipulada.
Apache MyFaces Trinidad versions 1.0.0 to 1.0.13, 1.2.1 to 1.2.14, 2.0.0 to 2.0.1, and 2.1.0 to 2.1.1 suffer from an information disclosure vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-05-24 CVE Reserved
- 2016-09-30 CVE Published
- 2024-08-06 CVE Updated
- 2025-04-12 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
http://packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Disclosure.html | Third Party Advisory |
|
http://www.securityfocus.com/bid/93236 | Third Party Advisory | |
http://www.securitytracker.com/id/1037633 | Third Party Advisory | |
https://www.oracle.com/security-alerts/cpujan2020.html | X_refsource_misc |
|
https://www.oracle.com/security-alerts/cpujul2020.html | X_refsource_misc |
|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Myfaces Trinidad Search vendor "Apache" for product "Myfaces Trinidad" | >= 1.0.0 < 1.0.13 Search vendor "Apache" for product "Myfaces Trinidad" and version " >= 1.0.0 < 1.0.13" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Myfaces Trinidad Search vendor "Apache" for product "Myfaces Trinidad" | >= 1.2.0 < 1.2.15 Search vendor "Apache" for product "Myfaces Trinidad" and version " >= 1.2.0 < 1.2.15" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Myfaces Trinidad Search vendor "Apache" for product "Myfaces Trinidad" | >= 2.0.0 < 2.0.2 Search vendor "Apache" for product "Myfaces Trinidad" and version " >= 2.0.0 < 2.0.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Myfaces Trinidad Search vendor "Apache" for product "Myfaces Trinidad" | >= 2.1.0 < 2.1.2 Search vendor "Apache" for product "Myfaces Trinidad" and version " >= 2.1.0 < 2.1.2" | - |
Affected
|