cbcvebase.
CVE-2006-7164
published 2007-03-20

CVE-2006-7164: SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security…

PriorityP415medium4.3CVSS 2.0
AVNACMAuNCPINAN
EPSS
1.44%
72.1th percentile
SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.

Affected

18 ranges
VendorProductVersion rangeFixed in
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
ibmwebsphere_application_server——
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.