Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:banking_enterprise_default_management",
"extracted_events": [
{
"last_affected": "2.10.0"
},
{
"last_affected": "2.12.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:banking_platform:2.12.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:banking_platform",
"extracted_events": [
{
"last_affected": "2.6.2"
},
{
"last_affected": "2.7.1"
},
{
"last_affected": "2.9.0"
},
{
"last_affected": "2.12.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_network_integrity",
"extracted_events": [
{
"last_affected": "7.3.6"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:communications_pricing_design_center",
"extracted_events": [
{
"last_affected": "12.0.0.3.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:hyperion_calculation_manager:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:hyperion_calculation_manager",
"extracted_events": [
{
"fixed": "11.2.8.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:retail_merchandising_system:19.0.1:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:retail_merchandising_system",
"extracted_events": [
{
"last_affected": "19.0.1"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:solaris_cluster:4.0:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:solaris_cluster",
"extracted_events": [
{
"last_affected": "4.0"
}
]
},
{
"source": "CPE_FIELD",
"cpes": [
"cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*"
],
"vendor_product": "oracle:time_and_labor",
"extracted_events": [
{
"introduced": "12.2.6"
},
{
"last_affected": "12.2.11"
}
]
}
]
}