VYPR
Unrated severityNVD Advisory· Published Jun 17, 2012· Updated Jun 16, 2026

CVE-2012-2672

CVE-2012-2672

Description

Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • cpe:2.3:a:oracle:mojarra:2.1.7:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:oracle:mojarra:2.1.7:*:*:*:*:*:*:*
    • (no CPE)range: = 2.1.7

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.