Security Advisory
CVE-2018-14371
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.