VYPR
Critical severity9.8NVD Advisory· Published Oct 3, 2016· Updated May 6, 2026

CVE-2016-5019

CVE-2016-5019

Description

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.myfaces.trinidad:trinidadMaven
>= 1.0.0, <= 1.0.13
org.apache.myfaces.trinidad:trinidadMaven
>= 1.2.0, < 1.2.151.2.15
org.apache.myfaces.trinidad:trinidadMaven
>= 2.0.0, < 2.0.22.0.2
org.apache.myfaces.trinidad:trinidadMaven
>= 2.1.0, < 2.1.22.1.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

17

News mentions

0

No linked articles in our index yet.