← Vulnerability feed

Vulnerability record · CVE-2019-17091 · published 2 October 2019

CVE-2019-17091: Eclipse mojarra cross-site scripting vulnerability

Eclipse · Mojarra

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

6.1 CVSS 3.1 Medium EPSS 2.5% · top 16.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
23Affected product versions listed by NVD
34References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2.2.20, allows Reflected XSS because a client window field is mishandled.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

23 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://bugs.eclipse.org/bugs/show_bug.cgi?id=548244 ExploitIssue TrackingPatchVendor Advisory
https://github.com/eclipse-ee4j/mojarra/commit/8f70f2bd024f00ecd5b3dcca45df73edda29dcee PatchThird Party Advisory
https://github.com/eclipse-ee4j/mojarra/commit/a3fa9573789ed5e867c43ea38374f4dbd5a8f81f PatchThird Party Advisory
https://github.com/eclipse-ee4j/mojarra/compare/2.3.9-RELEASE...2.3.10-RELEASE Release NotesThird Party Advisory
https://github.com/eclipse-ee4j/mojarra/files/3039198/advisory.txt ExploitThird Party Advisory
https://github.com/eclipse-ee4j/mojarra/issues/4556 Third Party Advisory
https://github.com/eclipse-ee4j/mojarra/pull/4567 PatchThird Party Advisory
https://github.com/javaserverfaces/mojarra/commit/ae1c234d0a6750822ac69d4ae26d90e3571f27fe PatchThird Party Advisory
https://github.com/javaserverfaces/mojarra/commit/f61935cd39f34329fbf27b1972a506fbdd0ab4d4 PatchThird Party Advisory
https://github.com/javaserverfaces/mojarra/compare/2.2.19...2.2.20 PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory
https://bugs.eclipse.org/bugs/show_bug.cgi?id=548244 ExploitIssue TrackingPatchVendor Advisory
https://github.com/eclipse-ee4j/mojarra/commit/8f70f2bd024f00ecd5b3dcca45df73edda29dcee PatchThird Party Advisory
https://github.com/eclipse-ee4j/mojarra/commit/a3fa9573789ed5e867c43ea38374f4dbd5a8f81f PatchThird Party Advisory
https://github.com/eclipse-ee4j/mojarra/compare/2.3.9-RELEASE...2.3.10-RELEASE Release NotesThird Party Advisory
https://github.com/eclipse-ee4j/mojarra/files/3039198/advisory.txt ExploitThird Party Advisory
https://github.com/eclipse-ee4j/mojarra/issues/4556 Third Party Advisory
https://github.com/eclipse-ee4j/mojarra/pull/4567 PatchThird Party Advisory
https://github.com/javaserverfaces/mojarra/commit/ae1c234d0a6750822ac69d4ae26d90e3571f27fe PatchThird Party Advisory
https://github.com/javaserverfaces/mojarra/commit/f61935cd39f34329fbf27b1972a506fbdd0ab4d4 PatchThird Party Advisory
https://github.com/javaserverfaces/mojarra/compare/2.2.19...2.2.20 PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpujul2020.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuoct2020.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html PatchThird Party Advisory

Track CVE-2019-17091 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-2555Oracle Coherence T3 deserialization allows unauthenticated remote code executionOracle Coherence (Fusion Middleware) deserializes untrusted data reachable over the T3 protocol, allowing an unauthenticated network attacker to exec…KEVEPSS 97%analysed9.8CVE-2017-9841PHPUnit eval-stdin.php remote PHP code executionPHPUnit before 4.8.28 and 5.x before 5.6.3 ships Util/PHP/eval-stdin.php, which evaluates HTTP POST body content as PHP when it begins with a "<?php …KEVEPSS 100%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2026-46924Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-35290Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-46876Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2022-23305Log4j 1.x JDBCAppender SQL injection via logged inputThe JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m mes…EPSS 67%analysed9.8CVE-2021-21783Genivia gsoap integer overflow vulnerabilityA code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead t…EPSS 5.3%

Source: NIST National Vulnerability Database (record CVE-2019-17091), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.