VulnerabilityModified
CVE-2020-6950
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
MEDIUM 6.5EPSS 10.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.1%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 10.12% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- eclipse/mojarra · oracle/banking enterprise default management · oracle/banking platform · oracle/communications network integrity · oracle/communications pricing design center · oracle/hyperion calculation manager · oracle/retail merchandising system · oracle/solaris cluster · oracle/time and labor
- Source
- cve@mitre.org
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943Issue Tracking, Vendor Advisory
- https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741Patch, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/issues/4571Issue Tracking, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943Issue Tracking, Vendor Advisory
- https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741Patch, Third Party Advisory
- https://github.com/eclipse-ee4j/mojarra/issues/4571Issue Tracking, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.