CVE-2020-6950
published 2021-06-02CVE-2020-6950: Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EXPLOIT
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mojarra | — | — |
| eclipse | mojarra | < 2.3.14 | 2.3.14 |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_enterprise_default_management | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | banking_platform | — | — |
| oracle | communications_network_integrity | — | — |
| oracle | communications_pricing_design_center | — | — |
| oracle | hyperion_calculation_manager | < 11.2.8.0 | 11.2.8.0 |
| oracle | retail_merchandising_system | — | — |
| oracle | solaris_cluster | — | — |
| oracle | time_and_labor | 12.2.6 – 12.2.11 | — |
| sailpoint | identityiq | < 8.1 | 8.1 |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | >= 8.1 < 8.1p7 | 8.1p7 |
| sailpoint | identityiq | >= 8.2 < 8.2p7 | 8.2p7 |
| sailpoint | identityiq | >= 8.3 < 8.3p4 | 8.3p4 |
| sailpoint | identityiq | >= 8.4 < 8.4p1 | 8.4p1 |