CVE-2020-6950
medium · 6.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
6.5
CVSS
10.1%
EPSS (exploit prob.)
95th
EPSS percentile
2021-06-02
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| eclipse | mojarra | < 2.3.14 |
| oracle | banking_enterprise_default_management | 2.10.0 |
| oracle | banking_enterprise_default_management | 2.12.0 |
| oracle | banking_platform | 2.6.2 |
| oracle | banking_platform | 2.7.1 |
| oracle | banking_platform | 2.9.0 |
| oracle | banking_platform | 2.12.0 |
| oracle | communications_network_integrity | 7.3.6 |
| oracle | communications_pricing_design_center | 12.0.0.3.0 |
| oracle | hyperion_calculation_manager | < 11.2.8.0 |
| oracle | retail_merchandising_system | 19.0.1 |
| oracle | solaris_cluster | 4.0 |
| oracle | time_and_labor | >= 12.2.6, <= 12.2.11 |
Check a specific version with /api/v1/cve/match.
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943
- https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741
- https://github.com/eclipse-ee4j/mojarra/issues/4571
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943
- https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741
- https://github.com/eclipse-ee4j/mojarra/issues/4571
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2020-6950