Back

CRITICAL

IdentityIQ JavaServer Faces File Path Traversal Vulnerability

Published Mar 22, 2024

Description

This vulnerability allows access to arbitrary files in the application server file system due to a path traversal vulnerability in JavaServer Faces (JSF) 2.2.20 documented in CVE-2020-6950. The remediation for this vulnerability contained in this security fix provides additional changes to the remediation announced in May 2021 tracked by ETN IIQSAW-3585 and January 2024 tracked by IIQFW-336. This vulnerability in IdentityIQ is assigned CVE-2024-2227.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner SailPoint
Published Mar 22, 2024
Updated Aug 1, 2024
Reserved Mar 6, 2024
CISA Vulnrichment
Updated Mar 30, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner SailPoint
Published Mar 22, 2024
Updated Aug 1, 2024
Exploited since n/a
EUVD-2024-27183