PT-2014-2169 · Apache · Apache Myfaces Core

Paul Nicolucci

·

Published

2014-06-19

·

Updated

2022-05-13

·

CVE-2011-4367

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache MyFaces Core versions 2.0.x through 2.0.11 Apache MyFaces Core versions 2.1.x through 2.1.5
Description Multiple directory traversal issues in Apache MyFaces Core allow remote attackers to read arbitrary files. This is achieved by including a .. (dot dot) in the ln parameter to the faces/javax.faces.resource/web.xml endpoint or in the PATH INFO to the faces/javax.faces.resource/ endpoint.
Recommendations For Apache MyFaces Core versions 2.0.x through 2.0.11, update to version 2.0.12 or later. For Apache MyFaces Core versions 2.1.x through 2.1.5, update to version 2.1.6 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4367
GHSA-GJFX-9WX3-J6R7

Affected Products

Apache Myfaces Core