CVE-2016-5019

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
03/10/2016
Last modified:
12/04/2025

Description

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:* 1.0.0 (including) 1.0.13 (excluding)
cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:* 1.2.0 (including) 1.2.15 (excluding)
cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:* 2.0.0 (including) 2.0.2 (excluding)
cpe:2.3:a:apache:myfaces_trinidad:*:*:*:*:*:*:*:* 2.1.0 (including) 2.1.2 (excluding)


References to Advisories, Solutions, and Tools