Critical severity9.8NVD Advisory· Published Oct 3, 2016· Updated May 6, 2026
CVE-2016-5019
CVE-2016-5019
Description
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.myfaces.trinidad:trinidadMaven | >= 1.0.0, <= 1.0.13 | — |
org.apache.myfaces.trinidad:trinidadMaven | >= 1.2.0, < 1.2.15 | 1.2.15 |
org.apache.myfaces.trinidad:trinidadMaven | >= 2.0.0, < 2.0.2 | 2.0.2 |
org.apache.myfaces.trinidad:trinidadMaven | >= 2.1.0, < 2.1.2 | 2.1.2 |
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
17- www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlnvdPatchWEB
- www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlnvdPatchWEB
- www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlnvdPatchWEB
- www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlnvdPatchWEB
- www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlnvdPatchWEB
- www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.htmlnvdPatchWEB
- mail-archives.apache.org/mod_mbox/myfaces-users/201609.mbox/%3CCAM1yOjYM%2BEW3mLUfX0pNAVLfUFRAw-Bhvkp3UE5%3DEQzR8Yxsfw%40mail.gmail.com%3EnvdMailing ListVendor AdvisoryWEB
- packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Disclosure.htmlnvdThird Party AdvisoryVDB EntryWEB
- www.securityfocus.com/bid/93236nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1037633nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-x7rc-4gqw-3q6qghsaADVISORY
- issues.apache.org/jira/browse/TRINIDAD-2542nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-5019ghsaADVISORY
- web.archive.org/web/20171129092136/http://www.securitytracker.com/id/1037633ghsaWEB
- web.archive.org/web/20210123173557/http://www.securityfocus.com/bid/93236ghsaWEB
- www.oracle.com/security-alerts/cpujan2020.htmlnvdWEB
- www.oracle.com/security-alerts/cpujul2020.htmlnvdWEB
News mentions
0No linked articles in our index yet.