Lucene search

K
cveMitreCVE-2020-6950
HistoryJun 02, 2021 - 4:15 p.m.

CVE-2020-6950

2021-06-0216:15:08
CWE-22
mitre
web.nvd.nist.gov
189
7
cve
2020
6950
directory traversal
eclipse mojarra
security vulnerability
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0.051

Percentile

93.1%

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

Affected configurations

Nvd
Node
eclipsemojarraRange<2.3.14
Node
oraclebanking_enterprise_default_managementMatch2.10.0
OR
oraclebanking_enterprise_default_managementMatch2.12.0
OR
oraclebanking_platformMatch2.6.2
OR
oraclebanking_platformMatch2.7.1
OR
oraclebanking_platformMatch2.9.0
OR
oraclebanking_platformMatch2.12.0
OR
oraclecommunications_network_integrityMatch7.3.6
OR
oraclecommunications_pricing_design_centerMatch12.0.0.3.0
OR
oraclehyperion_calculation_managerRange<11.2.8.0
OR
oracleretail_merchandising_systemMatch19.0.1
OR
oraclesolaris_clusterMatch4.0
OR
oracletime_and_laborRange12.2.612.2.11
VendorProductVersionCPE
eclipsemojarra*cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*
oraclebanking_enterprise_default_management2.10.0cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0:*:*:*:*:*:*:*
oraclebanking_enterprise_default_management2.12.0cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0:*:*:*:*:*:*:*
oraclebanking_platform2.6.2cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*
oraclebanking_platform2.7.1cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*
oraclebanking_platform2.9.0cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*
oraclebanking_platform2.12.0cpe:2.3:a:oracle:banking_platform:2.12.0:*:*:*:*:*:*:*
oraclecommunications_network_integrity7.3.6cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*
oraclecommunications_pricing_design_center12.0.0.3.0cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:*
oraclehyperion_calculation_manager*cpe:2.3:a:oracle:hyperion_calculation_manager:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

6.7

Confidence

High

EPSS

0.051

Percentile

93.1%