It was found that Mojarra JavaServer Faces did not properly escape user-supplied content in certain circumstances. Contents of outputText tags and raw EL expressions that immediately follow script or style elements were not escaped. A remote attacker could use a specially crafted URL to execute arbitrary web script in the user's browser.
Find out more about CVE-2013-5855 from the MITRE CVE dictionary dictionary and NIST NVD.
Base Score | 4.3 |
---|---|
Base Metrics | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Access Vector | Network |
Access Complexity | Medium |
Authentication | None |
Confidentiality Impact | None |
Integrity Impact | Partial |
Availability Impact | None |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat JBoss Operations Network 3.2 | RHSA-2014:0910 | 2014-07-21 |
Platform | Package | State |
---|---|---|
Red Hat Satellite 5.6 | JSF | Will not fix |
Red Hat Satellite 5.5 | JSF | Will not fix |
Red Hat Satellite 5.4 | JSF | Will not fix |
Red Hat JBoss Portal Platform 6 | JSF | Will not fix |
Red Hat JBoss Portal 5 | JSF | Will not fix |
Red Hat JBoss Fuse Service Works 6 | JSF | Will not fix |
Red Hat JBoss Enterprise SOA Platform 5 | JSF | Will not fix |
Red Hat JBoss Enterprise SOA Platform 4.3 | JSF | Will not fix |
Red Hat JBoss EWS 1 | JSF | Will not fix |
Red Hat JBoss EAP 6 | JSF | Will not fix |
Red Hat JBoss EAP 5 | JSF | Will not fix |
Red Hat JBoss Data Virtualization 6 | JSF | Will not fix |
Red Hat JBoss Data Grid 6 | JSF | Not affected |
Red Hat JBoss BRMS 6 | JSF | Will not fix |
Red Hat JBoss BRMS 5 | JSF | Will not fix |
Red Hat JBoss BPMS 6 | JSF | Will not fix |