Description
Directory traversal vulnerability in Apache Wicket 1.4.x before 1.4.20 and 1.5.x before 1.5.5 allows remote attackers to read arbitrary web-application files via a relative pathname in a URL for a Wicket resource that corresponds to a null package.
References (4)
Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_osvdb
http://osvdb.org/80301
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/52679
Vendor Advisory x_refsource_confirm
http://wicket.apache.org/2012/03/22/wicket-cve-2012-1089.html
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/74276
Scores
EPSS
0.0552
EPSS Percentile
91.8%
Details
CWE
CWE-22
Status
published
Products (25)
apache/wicket
1.4.0
apache/wicket
1.4.1
apache/wicket
1.4.2
apache/wicket
1.4.3
apache/wicket
1.4.4
apache/wicket
1.4.5
apache/wicket
1.4.6
apache/wicket
1.4.7
apache/wicket
1.4.8
apache/wicket
1.4.9
... and 15 more
Published
Mar 23, 2012
Tracked Since
Feb 18, 2026