CVE-2001-0312

IBM WebSphere Plugin - Unauthenticated JSP Source Code Disclosure via Host Header Manipulation

Title source: llm
STIX 2.1

Description

IBM WebSphere plugin for Netscape Enterprise server allows remote attackers to read source code for JSP files via an HTTP request that contains a host header that references a host that is not in WebSphere's host aliases list, which will bypass WebSphere processing.

References (1)

Core 1
Core References
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-01/0446.html

Scores

EPSS 0.0153
EPSS Percentile 72.1%

Details

Status published
Products (1)
ibm/websphere_plugin
Published Jun 02, 2001
Tracked Since Feb 18, 2026