Vulnerabilities > Oracle > Solaris Cluster > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-06-02 CVE-2020-6950 Path Traversal vulnerability in multiple products
Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.
network
low complexity
eclipse oracle CWE-22
6.5
2021-04-13 CVE-2021-29425 Path Traversal vulnerability in multiple products
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling code would use the result to construct a path value.
network
high complexity
apache debian oracle netapp CWE-22
4.8
2018-04-19 CVE-2018-2822 Unspecified vulnerability in Oracle Solaris Cluster 4.3
Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: Cluster Geo).
local
low complexity
oracle
6.6
2016-07-21 CVE-2016-3480 Unspecified vulnerability in Oracle Solaris Cluster 3.3/4.3
Unspecified vulnerability in the Solaris Cluster component in Oracle Sun Systems Products Suite 3.3 and 4.3 allows local users to affect confidentiality via vectors related to HA for Postgresql.
local
low complexity
oracle
4.4