Medium severity6.5NVD Advisory· Published Jun 2, 2021· Updated Jun 17, 2026
CVE-2020-6950
CVE-2020-6950
Description
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.glassfish:mojarra-parentMaven | < 2.3.14 | 2.3.14 |
Affected products
14cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:banking_platform:2.12.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:hyperion_calculation_manager:*:*:*:*:*:*:*:*Range: <11.2.8.0
- cpe:2.3:a:oracle:retail_merchandising_system:19.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:solaris_cluster:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*Range: >=12.2.6,<=12.2.11
Patches
Vulnerability mechanics
References
8- github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741nvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdPatchThird Party AdvisoryWEB
- bugs.eclipse.org/bugs/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-rpq8-mmwh-q9hmghsaADVISORY
- github.com/eclipse-ee4j/mojarra/issues/4571nvdIssue TrackingThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-6950ghsaADVISORY
News mentions
0No linked articles in our index yet.