Oracle Mojarra contains a flaw that may lead to an unauthorized information disclosure. The issue is triggered by an error in the FacesContext object when it fails to sanitize FacesContext references, which will disclose WAR resource information to a remote attacker when a call is sent to the Faces.Context.getCurrentInstance() function.
Classification
Location:
Remote / Network Access
Attack Type:
Information Disclosure
Impact:
Loss of Confidentiality
Solution:
Solution Unknown
Exploit:
Exploit Public
Disclosure:
Vendor Verified
Solution
OSVDB is not aware of a solution for this vulnerability.