CVE-2001-0446Path Equivalence: 'filename/' (Trailing Slash) in IBM Websphere Commerce Suite

Severity
5.0MEDIUMNVD
EPSS
0.6%
top 31.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 18
Latest updateApr 30

Description

IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-3hgh-j2c9-7c7j: IBM WCS (WebSphere Commerce Suite) 42022-04-30
CVEList
CVE-2001-0446: IBM WCS (WebSphere Commerce Suite) 42001-05-24

📐Framework References

3
CWE
Path Equivalence: 'filename/' (Trailing Slash)
CWE
Improper Resolution of Path Equivalence
CWE
Improper Neutralization of Trailing Special Elements
CVE-2001-0446 — IBM vulnerability | cvebase