CVE-2024-2227
published 2024-03-22CVE-2024-2227: This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF)…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.78%
51.9th percentile
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and January 2024 tracked by IIQFW-336. This vulnerability in IdentityIQ is assigned CVE-2024-2227.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sailpoint | identityiq | < 8.1 | 8.1 |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
| sailpoint | identityiq | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-84w8-jv98-6r25: This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (J
ghsa_unreviewed·2024-03-22·CVSS 6.5
CVE-2024-2227 [MEDIUM] CWE-22 GHSA-84w8-jv98-6r25: This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (J
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and January 2024 tracked by IIQFW-336. This vulnerability in IdentityIQ is assigned CVE-2024-2227.
Red Hat
kernel: ALSA: usb-audio: Stop parsing channels bits when all channels are found.
vendor_redhat·2024-05-17·CVSS 5.5
CVE-2024-27436 [MEDIUM] kernel: ALSA: usb-audio: Stop parsing channels bits when all channels are found.
kernel: ALSA: usb-audio: Stop parsing channels bits when all channels are found.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Stop parsing channels bits when all channels are found.
If a usb audio device sets more bits than the amount of channels
it could write outside of the map array.
In the Linux kernel, the following vulnerability has been resolved:
ALSA: usb-audio: Stop parsing channels bits when all channels are found.
The Linux kernel CVE team has assigned CVE-2024-27436 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024051711-CVE-2024-27436-2227@gregkh/T
Package: kernel (Red Hat Enterprise Linux 6) - Out of support scope
Package: kernel (Red Hat Enterprise Linux 7) - Out of support scope
Package: kernel-rt
No detection rules found.
No public exploits indexed.
2024-03-22
Published