MyFaces 2 will re-evaluate param/model values as EL expressions when includeViewParameters is set to true. This flaw allows an attacker to inject EL expressions. External References: https://issues.apache.org/jira/browse/MYFACES-3405 http://www.jakobk.com/2011/11/jsf-value-expression-injection-vulnerability/
Statement: Not vulnerable. This issue affects the MyFaces 2 package, which is not shipped with any Red Hat products.
*** This bug has been marked as a duplicate of bug 760692 ***
This CVE was rejected as a duplicate of CVE-2011-4343, so I'm removing the CVE references.