Skip to main content

Vendor/product archive

apache / myfaces CVEs

Beta · best-effort

5 CVEs tagged to apache / myfaces0 Critical, 2 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2021-26296

Published Feb 19, 2021

In the default configuration, Apache MyFaces Core versions 2.2.0 to 2.2.13, 2.3.0 to 2.3.7, 2.3-next-M1 to 2.3-next-M4, and 3.0.0-RC1 use cryptographically weak implicit and expli…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4343

Published Aug 8, 2017

Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4367

Published Jun 19, 2014

Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arb…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2057

Published Oct 20, 2010

shared/util/StateUtils.java in Apache MyFaces 1.1.x before 1.1.8, 1.2.x before 1.2.9, and 2.0.x before 2.0.1 uses an encrypted View State without a Message Authentication Code (MA…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2086

Published May 27, 2010

Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attacke…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1