CVE-2016-5019

Description

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.

Risk Information

Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
6.021

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-5019 are fixed in Apache-trinidad 1.2.15Windows
Vulnerabilities CVE-2016-5019 are fixed in Apache-trinidad 2.0.2Windows
Vulnerabilities CVE-2016-5019 are fixed in Apache-trinidad 2.1.2Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 8.3Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 8.4Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 15.1Windows
Multiple vulnerabilities are affected in Oracle Primavera P6 Enterprise Project Portfolio Management 15.2Windows
Vulnerabilities CVE-2016-5019 are affected in Apache-trinidad 1.0.13Windows
Vulnerabilities CVE-2016-5019 are fixed in Apache-trinidad for Linux 1.2.15Linux
Vulnerabilities CVE-2016-5019 are fixed in Apache-trinidad for Linux 2.0.2Linux
Vulnerabilities CVE-2016-5019 are fixed in Apache-trinidad for Linux 2.1.2Linux
Vulnerabilities CVE-2016-5019 are affected in Apache-trinidad for Linux 1.0.13Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234