---
cve: "CVE-2016-5019"
severity: "LOW"
cvss: 3.1
epss: "8%"
vendor: "n/a"
kev: false
exploited: false
published: "2016-10-03 18:59:04"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-13T09:08:59+02:00"
---

# CVE-2016-5019

> 3.1 LOW · 🧪 PoC

## Beschreibung

CoreResponseStateManager in Apache MyFaces Trinidad 1.0.0 through 1.0.13, 1.2.x before 1.2.15, 2.0.x before 2.0.2, and 2.1.x before 2.1.2 might allow attackers to conduct deserialization attacks via a crafted serialized view state string.

## Patch verfügbar (OSV)

- 859ef660eb7362863208cfdc254b3a73f414dbe4 (Commit)
- 38e019904dd58b1c45e62bb1cb7d2da58ef2ccb6 (Commit)

## Referenzen

- <http://mail-archives.apache.org/mod_mbox/myfaces-users/201609.mbox/%3CCAM1yOjYM%2BEW3mLUfX0pNAVLfUFRAw-Bhvkp3UE5%3DEQzR8Yxsfw%40mail.gmail.com%3E>
- <http://www.securityfocus.com/bid/93236>
- <http://www.securitytracker.com/id/1037633>
- <http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html>
- <http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html>
- <http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html>
- <https://www.oracle.com/security-alerts/cpujul2020.html>
- <http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html>
- <https://www.oracle.com/security-alerts/cpujan2020.html>
- <http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html>
- <http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html>
- <http://packetstormsecurity.com/files/138920/Apache-MyFaces-Trinidad-Information-Disclosure.html>
- <https://issues.apache.org/jira/browse/TRINIDAD-2542>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2016-5019) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
