CVE-2020-6950
published 2021-06-02CVE-2020-6950: Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
PriorityP351medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EXPLOIT
EPSS
10.12%
95.1th percentile
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mojarra | — | — |
| eclipse | mojarra | < 2.3.14 | 2.3.14 |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | communications_network_integrity | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | hyperion_calculation_manager | < 11.2.8.0 | 11.2.8.0 |
| oracle | retail_merchandising_system | — | — |
| oracle | solaris_cluster | — | — |
| oracle | time_and_labor | 12.2.6 – 12.2.11 | — |
| sailpoint | identityiq | < 8.1 | 8.1 |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | >= 8.1 < 8.1p7 | 8.1p7 |
| sailpoint | identityiq | >= 8.2 < 8.2p7 | 8.2p7 |
| sailpoint | identityiq | >= 8.3 < 8.3p4 | 8.3p4 |
| sailpoint | identityiq | >= 8.4 < 8.4p1 | 8.4p1 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect exploitation attempts by matching HTTP GET requests to paths containing '/javax.faces.resources/' with traversal sequences in 'loc' or 'con' parameters targeting WEB-INF ↗
- →Successful exploitation returns HTTP 200 with Content-Type 'application/xml' and body containing XML tags indicative of web.xml or faces-config.xml disclosure ↗
- →Fingerprint Eclipse Mojarra / JSF-based applications for attack surface identification using HTML body strings 'javax.faces.ViewState', 'javax.faces.viewstate', or 'javax.faces.resource' ↗
- ·The vulnerability affects Eclipse Mojarra versions before 2.3.14; the directory traversal is triggered via the 'loc' or 'con' HTTP parameters ↗
- ·The Nuclei template uses stop-at-first-match across 4 request variants, meaning detection tooling should probe all four URL patterns if not using this flag ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_oracle7.5MEDIUM
vendor_redhat7.5HIGH
vendor_debian6.5LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Eclipse Mojarra) — CVE-2020-6950
vendor_oracle·2023-04-15·CVSS 6.5
CVE-2020-6950 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Eclipse Mojarra) — CVE-2020-6950
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Eclipse Mojarra) vulnerability
CVE: CVE-2020-6950
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Eclipse Mojarra) — CVE-2020-6950
vendor_oracle·2022-10-15·CVSS 6.5
CVE-2020-6950 [MEDIUM] Oracle Oracle Communications Risk Matrix: Platform (Eclipse Mojarra) — CVE-2020-6950
Oracle Oracle Communications Risk Matrix: Platform (Eclipse Mojarra) vulnerability
CVE: CVE-2020-6950
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Installer (Eclipse Mojarra) — CVE-2020-6950
vendor_oracle·2022-04-15·CVSS 6.5
CVE-2020-6950 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Installer (Eclipse Mojarra) — CVE-2020-6950
Oracle Oracle Communications Applications Risk Matrix: Installer (Eclipse Mojarra) vulnerability
CVE: CVE-2020-6950
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle E-Business Suite Risk Matrix: Timecard (Eclipse Mojarra) — CVE-2020-6950
vendor_oracle·2022-01-15·CVSS 6.5
CVE-2020-6950 [MEDIUM] Oracle Oracle E-Business Suite Risk Matrix: Timecard (Eclipse Mojarra) — CVE-2020-6950
Oracle Oracle E-Business Suite Risk Matrix: Timecard (Eclipse Mojarra) vulnerability
CVE: CVE-2020-6950
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Services Manager (Eclipse Mojarra) — CVE-2020-6950
vendor_oracle·2021-10-15·CVSS 6.5
CVE-2020-6950 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Services Manager (Eclipse Mojarra) — CVE-2020-6950
Oracle Oracle Communications Applications Risk Matrix: Services Manager (Eclipse Mojarra) vulnerability
CVE: CVE-2020-6950
CVSS: 6.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Red Hat
Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
vendor_redhat·2020-02-20·CVSS 7.5
CVE-2020-6950 [HIGH] CWE-22 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
A flaw was found in Eclipse Mojarra before version 2.3.14, where it is vulnerable to a path traversal flaw via the loc parameter or the con parameter. An attacker could exploit this flaw to read arbitrary files.
Mitigation: There is no currently known mitigation for this flaw.
Package: jsf-impl (Red Hat Decision Manager 7) - Not affected
Package: jsf-impl (Red Hat JBoss Enterprise Application Platform 6) - Out of support scope
Package: jsf-impl (Red Hat JBoss Fuse 6) - Out of support scope
Package: jsf-impl (Red Hat JBoss Fuse Service Works 6) -
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Web Container (JavaServer Faces) — CVE-2020-6950
vendor_oracle·2020-01-15·CVSS 7.5
CVE-2020-6950 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Web Container (JavaServer Faces) — CVE-2020-6950
Oracle Oracle Fusion Middleware Risk Matrix: Web Container (JavaServer Faces) vulnerability
CVE: CVE-2020-6950
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2020 (JAN 2020)
Debian
CVE-2020-6950: mojarra - Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read ar...
vendor_debian·2020·CVSS 6.5
CVE-2020-6950 [MEDIUM] CVE-2020-6950: mojarra - Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read ar...
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-84w8-jv98-6r25: This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (J
ghsa_unreviewed·2024-03-22·CVSS 6.5
CVE-2024-2227 [MEDIUM] CWE-22 GHSA-84w8-jv98-6r25: This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (J
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and January 2024 tracked by IIQFW-336. This vulnerability in IdentityIQ is assigned CVE-2024-2227.
GHSA
GHSA-rhj5-wv7v-f365: IdentitylQ 8
ghsa_unreviewed·2023-01-31·CVSS 6.5
CVE-2022-46835 [MEDIUM] CWE-22 GHSA-rhj5-wv7v-f365: IdentitylQ 8
IdentitylQ 8.3 and all 8.3 patch levels prior to 8.3p2, IdentitylQ 8.2 and all 8.2 patch levels prior to 8.2p5, IdentitylQ 8.1 and all 8.1 patch levels prior to 8.1p7, Identity|Q 8.0 and all 8.0 patch levels prior to 8.0p6 allow access to arbitrary files in the application server filesystem due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950.
GHSA
Directory traversal in Eclipse Mojarra
ghsa·2021-09-01
CVE-2020-6950 [HIGH] CWE-22 Directory traversal in Eclipse Mojarra
Directory traversal in Eclipse Mojarra
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
OSV
Directory traversal in Eclipse Mojarra
osv·2021-09-01
CVE-2020-6950 [HIGH] Directory traversal in Eclipse Mojarra
Directory traversal in Eclipse Mojarra
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
No detection rules found.
Nuclei
Eclipse Mojarra - Local File Read
nuclei·CVSS 6.5
CVE-2020-6950 [MEDIUM] Eclipse Mojarra - Local File Read
Eclipse Mojarra - Local File Read
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
Template:
id: CVE-2020-6950
info:
name: Eclipse Mojarra - Local File Read
author: iamnoooob,pdresearch
severity: medium
description: |
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
impact: |
Attackers can read arbitrary files from the server including configuration files and credentials, potentially leading to further exploitation and data exposure.
remediation: |
Upgrade to Eclipse Mojarra version 2.3.14 or later.
reference:
- https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741
- https://github.com
Bugzilla
CVE-2020-6950 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
bugzilla·2020-02-20·CVSS 7.5
CVE-2020-6950 [HIGH] CVE-2020-6950 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
CVE-2020-6950 Mojarra: Path traversal via either the loc parameter or the con parameter, incomplete fix of CVE-2018-14371
Eclipse Mojarra before version 2.3.14 is vulnerable to a path traversal flaw via either the loc parameter or the con parameter. An attacker could exploit this to read arbitrary files. It was reported as CVE-2019-0199, but it was an incomplete fix.
Upstream Patch:
https://github.com/eclipse-ee4j/mojarra/commit/1b434748d9239f42eae8aa7d37d7a0930c061e24
https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741
Discussion:
External References:
https://github.com/javaserverfaces/mojarra/issues/4364
https://github.com/eclipse-ee4j/mojarra/commit/1b434748d9239f42eae8aa7d37d7a0930c061e24
https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943
http
arXiv
On the Use of Fine-grained Vulnerable Code Statements for Software Vulnerability Assessment Models
arxiv_fulltext·2022-03-16
On the Use of Fine-grained Vulnerable Code Statements for Software Vulnerability Assessment Models
On the Use of Fine-grained Vulnerable Code Statements for Software Vulnerability Assessment Models
Triet Huynh Minh Le
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide
Adelaide
Australia
[email protected]
M. Ali Babar
CREST - The Centre for Research on Engineering Software Technologies, The University of Adelaide
Adelaide
Australia
Cyber Security Cooperative Research Centre, Australia
[email protected]
## Abstract
Many studies have developed Machine Learning (ML) approaches to detect Software Vulnerabilities (SVs) in functions and fine-grained code statements that cause such SVs.
However, there is little work on leveraging such detection outputs for data-driven SV assessment to give information about exploitability, impa
https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741https://github.com/eclipse-ee4j/mojarra/issues/4571https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://bugs.eclipse.org/bugs/show_bug.cgi?id=550943https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741https://github.com/eclipse-ee4j/mojarra/issues/4571https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-06-02
Published