Skip to main content

CVE-2018-14371

Severity

6.5

Description

The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.

Project

Apache TomEE

Category
n/a
Tags
data
Date Disclosed

2018-07-18

Date Discovered

2018-07-17

Apache TomEE 8.0.x

First release:
2019-09-13
CVEs:
88
Support Lifecycle:
Namespace:
javax
Feel Vulnerable? 

Contact us so we can help you.

* These fields are required.