CVE-2010-2086
Apache MyFaces Cross-site Scripting vulnerability
EPSS 2.9%
Description
Apache MyFaces 1.1.7 and 1.2.8 (All previous versions are likely vulnerable), as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
How to fix CVE-2010-2086
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Maven/org.apache.myfaces.core:myfaces-core-module—no fix listed
Is CVE-2010-2086 being exploited?
Low — EPSS is 2.9%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, <= 1.1.7