ZeroHour

CVE-2020-6950

CVSS 3.1
6.5 medium
EPSS
10%p95
Published
()
Modified
Description

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

Vendors
eclipseoracle
Products
mojarra, banking enterprise default management, banking platform, communications network integrity, communications pricing design center, hyperion calculation manager, retail merchandising system, solaris cluster, time and labor
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.