CVE-2012-2672

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/06/2012
Last modified:
11/04/2025

Description

Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oracle:mojarra:2.1.7:*:*:*:*:*:*:*