Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Oracle Mojarra 2.2.x before 2.2.6 and 2.1.x before 2.1.28 does not perform appropriate encoding when a (1) <h:outputText> tag or (2) EL expression is used after a scriptor style block, which allows remote attackers to conduct cross-site scripting (XSS) attacks via application-specific vectors.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle JDeveloper 安全漏洞
Vulnerability Description
Oracle Jdeveloper是美国甲骨文(Oracle)公司的一套免费的集成开发环境(IDE),它可简化基于Java的SOA和Java EE应用程序开发,并支持整个开发生命周期。 Oracle Fusion Middleware 11.1.2.4.0和12.1.2.0.0版本的Oracle JDeveloper组件中的JavaServer Faces子组件存在安全漏洞。远程攻击者可利用该漏洞更新、插入或删除数据,影响数据的完整性。
CVSS Information
N/A
Vulnerability Type
N/A