Cryptographic Issues
CVE-2010-2057
Summary
File "shared/util/StateUtils.java" in Apache MyFaces 1.1.x prior to 1.1.8, 1.2.x prior to 1.2.9, and 2.0.x prior to 2.0.1 uses an encrypted View State without a Message Authentication Code (MAC), which makes it easier for remote attackers to perform successful modifications of the View State via a padding oracle attack.
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-310 - Cryptographic Issues
Cryptographic issues is a category of weaknesses related to the design and implementation of the confidentiality and integrity of data. If not addressed, the weaknesses in this category can lead to data quality degradation.
Advisory Timeline
- Published