5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:N/C:P/I:N/A:N
0.931 High
EPSS
Percentile
99.1%
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a ..
(dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml
or (2) the PATH_INFO
to faces/javax.faces.resource/
.
CPE | Name | Operator | Version |
---|---|---|---|
org.apache.myfaces.core:myfaces-impl | lt | 2.1.6 | |
org.apache.myfaces.core:myfaces-impl | lt | 2.0.12 |
mail-archives.apache.org/mod_mbox/myfaces-announce/201202.mbox/%3C4F33ED1F.4070007%40apache.org%3E
seclists.org/fulldisclosure/2012/Feb/150
exchange.xforce.ibmcloud.com/vulnerabilities/73100
github.com/advisories/GHSA-gjfx-9wx3-j6r7
nvd.nist.gov/vuln/detail/CVE-2011-4367
web.archive.org/web/20120213042504/www.securityfocus.com/bid/51939