{"id":"CVE-2011-4367","description":"Multiple directory traversal vulnerabilities in MyFaces JavaServer Faces (JSF) in Apache MyFaces Core 2.0.x before 2.0.12 and 2.1.x before 2.1.6 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) ln parameter to faces/javax.faces.resource/web.xml or (2) the PATH_INFO to faces/javax.faces.resource/.","cvssScore":5,"cvssVersion":"2.0","cvssVector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","cvssMetrics":[{"version":"2.0","score":5,"vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-22"],"resolved":"MITIGATED-BY-RASP","published":"2014-06-19","lastModified":"2026-06-16","affectedProducts":[{"vendor":"apache","product":"myfaces","versionStart":"\u003e=2.0.1","versionEnd":"\u003c=2.0.11"},{"vendor":"apache","product":"myfaces","versionStart":"\u003e=2.1.0","versionEnd":"\u003c=2.1.5"}],"totalAffectedProducts":1,"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/73100","source":"osv","tags":["WEB"]},{"url":"https://web.archive.org/web/20120213042504/http://www.securityfocus.com/bid/51939","source":"osv","tags":["WEB"]},{"url":"http://mail-archives.apache.org/mod_mbox/myfaces-announce/201202.mbox/%3C4F33ED1F.4070007%40apache.org%3E","source":"osv","tags":["WEB"]},{"url":"http://seclists.org/fulldisclosure/2012/Feb/150","source":"osv","tags":["WEB"]},{"url":"http://osvdb.org/show/osvdb/79002","source":"secalert@redhat.com","tags":["Broken Link"]},{"url":"http://secunia.com/advisories/47973","source":"secalert@redhat.com","tags":["Third Party Advisory"]},{"url":"http://www.securityfocus.com/bid/51939","source":"secalert@redhat.com","tags":["Exploit","Third Party Advisory","VDB Entry"]}],"reasoning":{"decidingSource":"secure-rule-match","decidingReason":"Promoted to MITIGATED-BY-RASP (security rule): this CVE's weakness (CWE-22: Path Traversal) can be mitigated by an ARMR path-traversal security rule that blocks this class of attack at the JVM level, without requiring a CVE-specific patch.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"no-match"},{"rule":"non-java-upstream","stage":"scope","outcome":"no-match"},{"rule":"oracle-component","stage":"scope","outcome":"no-match"},{"rule":"osv-maven","stage":"scope","outcome":"matched","status":"QUEUED-FOR-REVIEW","detail":"Maven packages: org.apache.myfaces.core:myfaces-impl"},{"rule":"patch-hint","stage":"disposition","outcome":"no-match"},{"rule":"open-source-maven","stage":"disposition","outcome":"matched","status":"MITIGATION-CANDIDATE","detail":"Open-source Maven artifact indexed by OSV (Maven packages: org.apache.myfaces.core:myfaces-impl). The source is public, which makes an ARMR patch rule a candidate; nothing here establishes that one can be written."},{"rule":"poc-derivable","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit","stage":"disposition","outcome":"skipped"},{"rule":"secure-rule-match","stage":"disposition","outcome":"matched","status":"MITIGATED-BY-RASP","detail":"CWE-22 (Path Traversal) is mitigable by an ARMR path-traversal security rule.","decisive":true},{"rule":"below-action-threshold","stage":"disposition","outcome":"skipped"},{"rule":"no-exploit-published","stage":"disposition","outcome":"skipped"}],"affectedProducts":[{"vendor":"apache","product":"myfaces","isKnown":false,"cpe":"cpe:2.3:a:apache:myfaces:*:*:*:*:*:*:*:*"}],"affectedPackages":[{"name":"org.apache.myfaces.core:myfaces-impl","introduced":"2.0.0","fixed":"2.0.12"},{"name":"org.apache.myfaces.core:myfaces-impl","introduced":"2.1.0","fixed":"2.1.6"}]},"assessment":{"record":{"state":"active"},"protection":{"level":"full","mechanisms":["security-rule"]},"action":{"state":"available","type":"security-rule"},"review":{"state":"automated","basis":"inferred"}},"exploits":[{"source":"exploit-db","url":"https://www.exploit-db.com/exploits/36681","title":"Apache MyFaces - 'ln' Information Disclosure","date":"2012-02-09"}],"signals":{"hasPOC":true,"pocCount":1,"pocSources":["exploit-db"],"firstPOCDate":"2012-02-09"},"kev":{"inKEV":false},"epss":{"available":true,"score":0.33471,"percentile":0.98281},"ssvc":{"available":false}}