CVE-2005-4833
IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to…
Does this matter?
Lower severity and a low EPSS score (1.27%). Track it; it rarely justifies an emergency change on its own.
Description
IBM WebSphere Application Server (WAS) 6.0 before 20050201, when serving pages in an Application WAR or an Extended Document Root, allows remote attackers to obtain the JSP source code and other sensitive information via "a specific JSP URL," related to lack of normalization of the URL format.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
- EPSS
- 1.27% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- ibm/websphere application server
- Source
- cve@mitre.org
References
- http://osvdb.org/34177
- http://secunia.com/advisories/24478Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21243541Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24008815Patch, Vendor Advisory
- http://www.securityfocus.com/bid/22991
- http://www.vupen.com/english/advisories/2007/0970
- http://osvdb.org/34177
- http://secunia.com/advisories/24478Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21243541Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24008815Patch, Vendor Advisory
- http://www.securityfocus.com/bid/22991
- http://www.vupen.com/english/advisories/2007/0970
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.