Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | — | Upgrade payara | Oct 10, 2020 | Oct 6, 2020 |
| Oracle Ebs | — | Apply patch 30448458 for Oracle E-Business Suite version 12.2.8Apply the jan-2022 Critical Patch Update (CPU) (Patch 33487428) for Oracle E-Business SuiteApply patch 33568131 for Oracle E-Business Suite version 12.2.11Apply patch 33457157 for Oracle E-Business Suite version 12.2.10Apply patch 33457157 for Oracle E-Business Suite version 12.2.11Apply patch 33457157 for Oracle E-Business Suite version 12.2.9Apply patch 33457157 for Oracle E-Business Suite version 12.2.7Apply patch 30448458 for Oracle E-Business Suite version 12.2.11Apply patch 30448458 for Oracle E-Business Suite version 12.2.6Apply patch 30448458 for Oracle E-Business Suite version 12.2.10Apply patch 30448458 for Oracle E-Business Suite version 12.2.9Apply patch 33457157 for Oracle E-Business Suite version 12.2.8Apply patch 30448458 for Oracle E-Business Suite version 12.2.7Apply patch 33457157 for Oracle E-Business Suite version 12.2.6 | Jun 20, 2022 | Jun 2, 2021 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 35247514 for version 12.2.1.3.0. | Jun 2, 2021 | Jun 2, 2021 |
| Red Hat Jboss Eap | — | Upgrade Red Hat JBoss EAP to the latest version | Sep 19, 2024 | Feb 20, 2020 |
| Red_hat Jboss_eap | — | — | Apr 10, 2023 | Jun 2, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub