Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"extracted_events": [
{
"fixed": "11.2.8.0"
}
],
"vendor_product": "oracle:hyperion_calculation_manager",
"cpes": [
"cpe:2.3:a:oracle:hyperion_calculation_manager:*:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "12.2.6"
},
{
"last_affected": "12.2.11"
}
],
"vendor_product": "oracle:time_and_labor",
"cpes": [
"cpe:2.3:a:oracle:time_and_labor:*:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_STRING",
"extracted_events": [
{
"last_affected": "2.10.0"
},
{
"last_affected": "2.12.0"
}
],
"vendor_product": "oracle:banking_enterprise_default_management",
"cpes": [
"cpe:2.3:a:oracle:banking_enterprise_default_management:2.10.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_enterprise_default_management:2.12.0:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_STRING",
"extracted_events": [
{
"last_affected": "2.6.2"
},
{
"last_affected": "2.7.1"
},
{
"last_affected": "2.9.0"
},
{
"last_affected": "2.12.0"
}
],
"vendor_product": "oracle:banking_platform",
"cpes": [
"cpe:2.3:a:oracle:banking_platform:2.12.0:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.6.2:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.7.1:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:banking_platform:2.9.0:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_STRING",
"extracted_events": [
{
"last_affected": "7.3.6"
}
],
"vendor_product": "oracle:communications_network_integrity",
"cpes": [
"cpe:2.3:a:oracle:communications_network_integrity:7.3.6:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_STRING",
"extracted_events": [
{
"last_affected": "12.0.0.3.0"
}
],
"vendor_product": "oracle:communications_pricing_design_center",
"cpes": [
"cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_STRING",
"extracted_events": [
{
"last_affected": "19.0.1"
}
],
"vendor_product": "oracle:retail_merchandising_system",
"cpes": [
"cpe:2.3:a:oracle:retail_merchandising_system:19.0.1:*:*:*:*:*:*:*"
]
},
{
"source": "CPE_STRING",
"extracted_events": [
{
"last_affected": "4.0"
}
],
"vendor_product": "oracle:solaris_cluster",
"cpes": [
"cpe:2.3:a:oracle:solaris_cluster:4.0:*:*:*:*:*:*:*"
]
}
]
}{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:eclipse:mojarra:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.3.14"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-6950.json"
"2026-05-30T12:25:50Z"
[
{
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"digest": {
"function_hash": "202762170446459133786542832831365494378",
"length": 1102.0
},
"id": "CVE-2020-6950-1eec707c",
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "impl/src/main/java/com/sun/faces/application/resource/ClasspathResourceHelper.java",
"function": "findPathConsideringContracts"
}
},
{
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"digest": {
"line_hashes": [
"327922468738949009520665501875403193676",
"280557685043635043046617085761076948685",
"149614859817110160033372584879992522944",
"297201853854087322211814576356382111919"
],
"threshold": 0.9
},
"id": "CVE-2020-6950-202fe355",
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "impl/src/main/java/com/sun/faces/application/resource/WebappResourceHelper.java"
}
},
{
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"digest": {
"function_hash": "164793891236731149737771110254800422834",
"length": 753.0
},
"id": "CVE-2020-6950-3759e947",
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "impl/src/main/java/com/sun/faces/application/resource/ResourceManager.java",
"function": "getLocalePrefix"
}
},
{
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"digest": {
"line_hashes": [
"327922468738949009520665501875403193676",
"280557685043635043046617085761076948685",
"149614859817110160033372584879992522944",
"297201853854087322211814576356382111919"
],
"threshold": 0.9
},
"id": "CVE-2020-6950-704c57fb",
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "impl/src/main/java/com/sun/faces/application/resource/ClasspathResourceHelper.java"
}
},
{
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"digest": {
"function_hash": "92691063882270755257462325335720830765",
"length": 1113.0
},
"id": "CVE-2020-6950-98954b3c",
"signature_type": "Function",
"signature_version": "v1",
"target": {
"file": "impl/src/main/java/com/sun/faces/application/resource/WebappResourceHelper.java",
"function": "findPathConsideringContracts"
}
},
{
"source": "https://github.com/eclipse-ee4j/mojarra/commit/cefbb9447e7be560e59da2da6bd7cb93776f7741",
"deprecated": false,
"digest": {
"line_hashes": [
"253486533298527110866937080966426277777",
"317122338195403230137015481196474150719",
"152375503309331982662867029571013231594",
"254513352893525569632194411325804193789",
"22497317531715227242858893189539738053",
"110715861968449235095856192842044305285",
"173356329293226279929914073126971022580",
"118502403437888581242720108522154470160"
],
"threshold": 0.9
},
"id": "CVE-2020-6950-ebac085b",
"signature_type": "Line",
"signature_version": "v1",
"target": {
"file": "impl/src/main/java/com/sun/faces/application/resource/ResourceManager.java"
}
}
]