Vulnerability Description
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Mojarra | < 2.3.14 |
| Oracle | Banking Enterprise Default Management | 2.10.0 |
| Oracle | Banking Platform | 2.6.2 |
| Oracle | Communications Network Integrity | 7.3.6 |
| Oracle | Communications Pricing Design Center | 12.0.0.3.0 |
| Oracle | Hyperion Calculation Manager | < 11.2.8.0 |
| Oracle | Retail Merchandising System | 19.0.1 |
| Oracle | Solaris Cluster | 4.0 |
| Oracle | Time And Labor | >= 12.2.6, <= 12.2.11 |
Related Weaknesses (CWE)
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943Issue TrackingVendor Advisory
- https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb937PatchThird Party Advisory
- https://github.com/eclipse-ee4j/mojarra/issues/4571Issue TrackingThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatchThird Party Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=550943Issue TrackingVendor Advisory
- https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb937PatchThird Party Advisory
- https://github.com/eclipse-ee4j/mojarra/issues/4571Issue TrackingThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatchThird Party Advisory
FAQ
What is CVE-2020-6950?
CVE-2020-6950 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
How severe is CVE-2020-6950?
CVE-2020-6950 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6950?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Mojarra, Oracle Banking Enterprise Default Management, Oracle Banking Platform, Oracle Communications Network Integrity, Oracle Communications Pricing Design Center.