4.3
CVSSv2

CVE-2006-7164

Published: 20/03/2007 Updated: 05/09/2008
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

SimpleFileServlet in IBM WebSphere Application Server 5.0.1 up to and including 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote malicious users to read secure files and obtain sensitive information via certain requests.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm websphere_application_server 5.0.2.12

ibm websphere_application_server 5.0.2.14

ibm websphere_application_server 5.0.2.4

ibm websphere_application_server 5.0.2.6

ibm websphere_application_server 5.0.1

ibm websphere_application_server 5.0.2

ibm websphere_application_server 5.0.2.1

ibm websphere_application_server 5.0.2.10

ibm websphere_application_server 5.0.2.8

ibm websphere_application_server 5.0.2.9

ibm websphere_application_server 5.0.2.15

ibm websphere_application_server 5.0.2.16

ibm websphere_application_server 5.0.2.2

ibm websphere_application_server 5.0.2.3

ibm websphere_application_server 5.0.2.11

ibm websphere_application_server 5.0.2.13

ibm websphere_application_server 5.0.2.5

ibm websphere_application_server 5.0.2.7