Caucho Technology Resin Professional (Pro) 4.0.38

CPE Details

Caucho Technology Resin Professional (Pro) 4.0.38
4.0.38
2014-07-28
16h55 +00:00
2014-07-30
01h10 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:caucho:resin:4.0.38:*:*:*:professional:*:*:*

Informations

Vendor

caucho

Product

resin

Version

4.0.38

Software Edition

professional

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2014-2966 2014-07-26 13h00 +00:00 The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demonstrated by bypassing an XSS protection mechanism.
5
CVE-2010-2087 2010-05-27 18h32 +00:00 Oracle Mojarra 1.2_14 and 2.0.2, as used in IBM WebSphere Application Server, Caucho Resin, and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.
4.3