Back to Database
Status published
Medium
CVE-2020-6950
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to...
Vulnerability Description
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-6950
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://github.com/eclipse-ee4j/mojarra/issues/4571
- https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
More from eclipse
View All →CVE-2023-41900
Jetty's OpenId Revoked authentication allows one request
Low
3.5
CVE-2023-40167
Jetty accepts "+" prefixed value in Content-Length
Medium
5.3
CVE-2023-36479
Jetty vulnerable to errant command quoting in CGI Servlet
Low
3.5
CVE-2023-36478
HTTP/2 HPACK integer overflow and buffer allocation
High
7.5
CVE-2023-26049
Cookie parsing of quoted values can exfiltrate values from other cookies in Eclipse Jetty
Low
2.4
Affected Vendor
eclipse
View all reports →Affected Software
mojarra, banking enterprise default management, banking platform, communications network integrity, communications pricing design center, hyperion calculation manager, retail merchandising system, solaris cluster, time and labor
Vulnerable Versions:
0, 2.10.0, 2.12.0, 2.6.2, 2.7.1, 2.9.0, 7.3.6, 12.0.0.3.0, 19.0.1, 4.0, 12.2.6
Timeline
Official Publish:
June 2nd, 2021
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.