CVE-2006-3231IBM Websphere Application Server vulnerability

3 documents3 sources
Severity
4.3MEDIUMNVD
EPSS
0.8%
top 25.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 27
Latest updateMay 1

Description

Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 6.0.2.11, when fileServingEnabled is true, allows remote attackers to obtain JSP source code and other sensitive information via "URIs with special characters."

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hhmc-pjhr-jvpx: Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 62022-05-01
CVEList
CVE-2006-3231: Unspecified vulnerability in IBM WebSphere Application Server (WAS) before 62006-06-27
CVE-2006-3231 — IBM vulnerability | cvebase