{"id":"CVE-2010-2086","aliases":[],"url":"https://o3.security/vulnerability/CVE-2010-2086","summary":"Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers…","details":"Apache MyFaces 1.1.7 and 1.2.8, as used in IBM WebSphere Application Server and other applications, does not properly handle an unencrypted view state, which allows remote attackers to conduct cross-site scripting (XSS) attacks or execute arbitrary Expression Language (EL) statements via vectors that involve modifying the serialized view object.","published":"2010-05-27T19:00:01.063","modified":"2026-06-16T23:19:57.197","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf"},{"type":"WEB","url":"https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt"},{"type":"WEB","url":"http://www.blackhat.com/presentations/bh-dc-10/Byrne_David/BlackHat-DC-2010-Byrne-SGUI-slides.pdf"},{"type":"WEB","url":"https://www.trustwave.com/spiderlabs/advisories/TWSL2010-001.txt"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-16T23:19:57.197"}}