← All CVEs

CVE-2020-6950

medium · 6.5

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

6.5
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2021-06-02
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
eclipsemojarra< 2.3.14
oraclebanking_enterprise_default_management2.10.0
oraclebanking_enterprise_default_management2.12.0
oraclebanking_platform2.6.2
oraclebanking_platform2.7.1
oraclebanking_platform2.9.0
oraclebanking_platform2.12.0
oraclecommunications_network_integrity7.3.6
oraclecommunications_pricing_design_center12.0.0.3.0
oraclehyperion_calculation_manager< 11.2.8.0
oracleretail_merchandising_system19.0.1
oraclesolaris_cluster4.0
oracletime_and_labor>= 12.2.6, <= 12.2.11

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-6950