MEDIUM🇬🇧 English

CVE-2020-6950

CVSS 6.5v3.1pub. 2021-06-02upd. 2024-11-21

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
  • Eclipse Mojarra

    APP
    Eclipse
    < 2.3.14
  • Oracle Banking Enterprise Default Management

    APP
    Oracle
    2.10.02.12.0
  • Oracle Banking Platform

    APP
    Oracle
    2.12.02.6.22.7.12.9.0
  • Oracle Communications Network Integrity

    APP
    Oracle
    7.3.6
  • Oracle Communications Pricing Design Center

    APP
    Oracle
    12.0.0.3.0
  • Oracle Hyperion Calculation Manager

    APP
    Oracle
    < 11.2.8.0
  • Oracle Retail Merchandising System

    APP
    Oracle
    19.0.1
  • Oracle Solaris Cluster

    APP
    Oracle
    4.0
  • Oracle Time And Labor

    APP
    Oracle
    12.2.6 – 12.2.11
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Path Traversal
CWE
Referencje

Powiązane podatności

CVE-2022-22965CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+

CVE-2020-17530CRITICAL9.8⚠ KEVPL ✓ten sam produkt

RCE w Apache Struts 2 poprzez wymuszoną ewaluację OGNL

CVE-2026-60858CRITICAL9.8ten sam produkt

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). T...

CVE-2026-61206CRITICAL9.9ten sam produkt

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). T...

CVE-2026-62582CRITICAL9.6ten sam produkt

Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). T...