CVE-2011-4343

Description

Information disclosure vulnerability in Apache MyFaces Core 2.0.1 through 2.0.10 and 2.1.0 through 2.1.4 allows remote attackers to inject EL expressions via crafted parameters.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.864

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities are fixed in IBM WebSphere 8.0.0.15Windows
Multiple vulnerabilities are fixed in IBM WebSphere 8.5.5.13Windows
Vulnerabilities CVE-2011-4343 are fixed in Apache-myfaces-core-module 2.0.11Windows
Vulnerabilities CVE-2011-4343 are fixed in Apache-myfaces-core-module 2.1.5Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.2.3Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Vulnerabilities CVE-2011-4343 are fixed in Apache-myfaces-core-module for Linux 2.0.11Linux
Vulnerabilities CVE-2011-4343 are fixed in Apache-myfaces-core-module for Linux 2.1.5Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234