CVE-2016-5019: Apache Myfaces Trinidad
Critical severity, CVSS 9.8. EPSS: 8% chance of exploitation in the next 30 days.
CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.
Affected products
- Apache Myfaces Trinidad: from 1.0.0, before 1.0.13 (fixed in 1.0.13); from 1.2.0, before 1.2.15 (fixed in 1.2.15); from 2.0.0, before 2.0.2 (fixed in 2.0.2); from 2.1.0, before 2.1.2 (fixed in 2.1.2)
Published 2016-10-03. Last modified 2026-06-17.