Unrated severityNVD Advisory· Published Jun 17, 2012· Updated Jun 16, 2026
CVE-2012-2672
CVE-2012-2672
Description
Oracle Mojarra 2.1.7 does not properly "clean up" the FacesContext reference during startup, which allows local users to obtain context information an access resources from another WAR file by calling the FacesContext.getCurrentInstance function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:oracle:mojarra:2.1.7:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:mojarra:2.1.7:*:*:*:*:*:*:*
- (no CPE)range: = 2.1.7
Patches
Vulnerability mechanics
References
10- java.net/jira/browse/JAVASERVERFACES-2436nvdExploit
- secunia.com/advisories/49284nvdVendor Advisory
- rhn.redhat.com/errata/RHSA-2012-1591.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-1592.htmlnvd
- rhn.redhat.com/errata/RHSA-2012-1594.htmlnvd
- secunia.com/advisories/51607nvd
- www.openwall.com/lists/oss-security/2012/06/07/2nvd
- www.openwall.com/lists/oss-security/2012/06/07/3nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/76179nvd
- issues.jboss.org/browse/JBPAPP-9197nvd
News mentions
0No linked articles in our index yet.