This vulnerability allows access to arbitrary files in...
Critical severity
Unreviewed
Published
Mar 22, 2024
to the GitHub Advisory Database
•
Updated Mar 22, 2024
Description
Published by the National Vulnerability Database
Mar 22, 2024
Published to the GitHub Advisory Database
Mar 22, 2024
Last updated
Mar 22, 2024
This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and January 2024 tracked by IIQFW-336. This vulnerability in IdentityIQ is assigned CVE-2024-2227.
References