MyFaces: multiple directory traversal vulnerabilities allow remote attackers to read arbitrary files
Published Jun 19, 2014
7.5
HIGHCVSS 3.1
EPSS 33.75%
Description
Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml or (2) the PATH_INFO to faces/javax.faces.resource/.
Affected products
No data.
No data.
Red Hat BPM Suite 6
MyFaces
Not affected
Red Hat Decision Manager 7
MyFaces
Not affected
Red Hat JBoss Enterprise Application Platform 6
MyFaces
Not affected
Red Hat JBoss Enterprise Application Platform 7
MyFaces
Not affected
Red Hat JBoss Enterprise Application Platform Continuous Delivery
MyFaces
Not affected
Red Hat JBoss Fuse 6
MyFaces
Not affected
Red Hat Process Automation 7
MyFaces
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat BPM Suite 6 | MyFaces | Not affected | n/a |
| Red Hat Decision Manager 7 | MyFaces | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | MyFaces | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | MyFaces | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Continuous Delivery | MyFaces | Not affected | n/a |
| Red Hat JBoss Fuse 6 | MyFaces | Not affected | n/a |
| Red Hat Process Automation 7 | MyFaces | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (36 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 33.75% (0.33747) | 98.34th | v5 (v2026.06.15) |
| Jun 15, 2026 | 33.47% (0.33471) | 98.16th | v5 (v2026.06.15) |
| Mar 4, 2026 | 85.92% (0.85920) | 99.37th | v4 (v2025.03.14) |
| Mar 1, 2026 | 84.90% (0.84896) | 99.33th | v4 (v2025.03.14) |
| Feb 4, 2026 | 85.92% (0.85920) | 99.37th | v4 (v2025.03.14) |
| Feb 1, 2026 | 84.90% (0.84896) | 99.32th | v4 (v2025.03.14) |
| Jan 4, 2026 | 85.92% (0.85920) | 99.36th | v4 (v2025.03.14) |
| Jan 1, 2026 | 84.90% (0.84896) | 99.32th | v4 (v2025.03.14) |
| Dec 4, 2025 | 85.92% (0.85920) | 99.34th | v4 (v2025.03.14) |
| Dec 1, 2025 | 82.57% (0.82573) | 99.19th | v4 (v2025.03.14) |
| Nov 4, 2025 | 86.32% (0.86318) | 99.36th | v4 (v2025.03.14) |
| Nov 1, 2025 | 82.57% (0.82573) | 99.19th | v4 (v2025.03.14) |
| Oct 4, 2025 | 86.32% (0.86318) | 99.36th | v4 (v2025.03.14) |
| Oct 1, 2025 | 82.57% (0.82573) | 99.20th | v4 (v2025.03.14) |
| Sep 4, 2025 | 86.32% (0.86318) | 99.37th | v4 (v2025.03.14) |
| Sep 1, 2025 | 82.57% (0.82573) | 99.20th | v4 (v2025.03.14) |
| Aug 4, 2025 | 86.32% (0.86318) | 99.36th | v4 (v2025.03.14) |
| Aug 1, 2025 | 82.57% (0.82573) | 99.19th | v4 (v2025.03.14) |
| Jul 4, 2025 | 86.32% (0.86318) | 99.35th | v4 (v2025.03.14) |
| Jul 1, 2025 | 82.57% (0.82573) | 99.18th | v4 (v2025.03.14) |
| Jun 4, 2025 | 86.32% (0.86318) | 99.35th | v4 (v2025.03.14) |
| Jun 1, 2025 | 82.57% (0.82573) | 99.18th | v4 (v2025.03.14) |
| May 4, 2025 | 86.32% (0.86318) | 99.34th | v4 (v2025.03.14) |
| May 1, 2025 | 82.57% (0.82573) | 99.17th | v4 (v2025.03.14) |
| Mar 17, 2025 | 87.74% (0.87739) | 99.44th | v4 (v2025.03.14) |
| Dec 17, 2024 | 11.01% (0.11012) | 95.11th | v3 (v2023.03.01) |
| Dec 12, 2024 | 93.21% (0.93212) | 99.18th | v3 (v2023.03.01) |
| Jun 17, 2024 | 93.13% (0.93128) | 99.07th | v3 (v2023.03.01) |
| May 1, 2024 | 94.05% (0.94053) | 99.13th | v3 (v2023.03.01) |
| Mar 15, 2024 | 93.40% (0.93399) | 99.02th | v3 (v2023.03.01) |
| Oct 24, 2023 | 94.27% (0.94265) | 98.92th | v3 (v2023.03.01) |
| May 27, 2023 | 94.94% (0.94944) | 98.90th | v3 (v2023.03.01) |
| Mar 7, 2023 | 95.45% (0.95448) | 98.91th | v3 (v2023.03.01) |
| Mar 6, 2023 | 30.87% (0.30871) | 97.53th | v2 (v2022.01.01) |
| Dec 1, 2022 | 30.87% (0.30871) | 97.47th | v2 (v2022.01.01) |
| Feb 4, 2022 | 32.64% (0.32638) | 96.53th | v2 (v2022.01.01) |
References (12)
- http://mail-archives.apache.org/mod_mbox/myfaces-announce/201202.mbox/%3C4F33ED1F.4070007%40apache.org%3E mailing-listx_refsource_MLISTExploitVendor Advisory
- http://osvdb.org/show/osvdb/79002 vdb-entryx_refsource_OSVDBBroken Link
- http://seclists.org/fulldisclosure/2012/Feb/150 mailing-listx_refsource_FULLDISCExploitMailing ListThird Party Advisory
- http://secunia.com/advisories/47973 third-party-advisoryx_refsource_SECUNIAThird Party Advisory
- http://www.securityfocus.com/bid/51939 vdb-entryx_refsource_BIDExploitThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2011-4367 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1866260 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/73100 vdb-entryx_refsource_XFThird Party AdvisoryVDB Entry
- https://github.com/advisories/GHSA-gjfx-9wx3-j6r7 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2011-4367
- https://web.archive.org/web/20120213042504/http://www.securityfocus.com/bid/51939
- https://www.cve.org/CVERecord?id=CVE-2011-4367
Change history (0)
No recorded changes yet.