CVE-2013-5855

Related Vulnerabilities: CVE-2013-5855  

It was found that Mojarra JavaServer Faces did not properly escape user-supplied content in certain circumstances. Contents of outputText tags and raw EL expressions that immediately follow script or style elements were not escaped. A remote attacker could use a specially crafted URL to execute arbitrary web script in the user's browser.

It was found that Mojarra JavaServer Faces did not properly escape user-supplied content in certain circumstances. Contents of outputText tags and raw EL expressions that immediately follow script or style elements were not escaped. A remote attacker could use a specially crafted URL to execute arbitrary web script in the user's browser.

Find out more about CVE-2013-5855 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v2 metrics

Base Score 4.3
Base Metrics AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None

Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Operations Network 3.2 RHSA-2014:0910 2014-07-21

Affected Packages State

Platform Package State
Red Hat Satellite 5.6 JSF Will not fix
Red Hat Satellite 5.5 JSF Will not fix
Red Hat Satellite 5.4 JSF Will not fix
Red Hat JBoss Portal Platform 6 JSF Will not fix
Red Hat JBoss Portal 5 JSF Will not fix
Red Hat JBoss Fuse Service Works 6 JSF Will not fix
Red Hat JBoss Enterprise SOA Platform 5 JSF Will not fix
Red Hat JBoss Enterprise SOA Platform 4.3 JSF Will not fix
Red Hat JBoss EWS 1 JSF Will not fix
Red Hat JBoss EAP 6 JSF Will not fix
Red Hat JBoss EAP 5 JSF Will not fix
Red Hat JBoss Data Virtualization 6 JSF Will not fix
Red Hat JBoss Data Grid 6 JSF Not affected
Red Hat JBoss BRMS 6 JSF Will not fix
Red Hat JBoss BRMS 5 JSF Will not fix
Red Hat JBoss BPMS 6 JSF Will not fix

External References