Описание
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
Меры по смягчению последствий
There is no currently known mitigation for this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| JBoss Developer Studio 11 | mojarra | Out of support scope | ||
| Red Hat BPM Suite 6 | mojarra | Out of support scope | ||
| Red Hat JBoss BRMS 6 | mojarra | Out of support scope | ||
| Red Hat JBoss Data Grid 6 | mojarra | Out of support scope | ||
| Red Hat JBoss Data Virtualization 6 | mojarra | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 6 | mojarra | Out of support scope | ||
| Red Hat JBoss Fuse 6 | mojarra | Out of support scope | ||
| Red Hat JBoss Operations Network 3 | mojarra | Out of support scope | ||
| Red Hat JBoss SOA Platform 5 | mojarra | Out of support scope | ||
| EAP-CD 20 Tech Preview | jsf-impl | Fixed | RHSA-2020:3585 | 31.08.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarr ...
Уязвимость функции getLocalePrefix (ResourceManager.java) библиотеки Eclipse Mojarra, как реализации EE4J Eclipse для спецификации Jakarta Faces, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
5.5 Medium
CVSS3