4
CVSSv2

CVE-2006-3921

Published: 28/07/2006 Updated: 20/07/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Sun Java System Application Server (SJSAS) 7 up to and including 8.1 and Web Server (SJSWS) 6.0 and 6.1 allows remote authenticated users to read files outside of the "document root directory" via a direct request using a UTF-8 encoded URI.

Vulnerable Product Search on Vulmon Subscribe to Product

sun java system application server 7.0

sun java system application server 8.1

sun java system web server 6.0

sun java system application server 7.1

sun java system web server 6.1