« Back to list

Primetek

Primetek Primefaces: vulnerabilities and CVEs

Primetek Primefaces has 2 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 1 are listed by CISA as actively exploited.

CVEs2
Last 12 months0
Critical1
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2017-1000486Critical (9.8)94%⚠ Active exploitationJan 3, 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2020-10544Medium (6.1)0.83%—Mar 13, 2020
An XSS issue was discovered in tooltip/tooltip.js in PrimeTek PrimeFaces 7.0.11. In a web application using PrimeFaces, an attacker can provide JavaScript code in an input field whose data is later used as a tooltip…
CVE-2017-1000486Critical (9.8)94%⚠ Active exploitationJan 3, 2018
Primetek Primefaces 5.x is vulnerable to a weak encryption flaw resulting in remote code execution

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.