CVE-2001-0446

IBM WebSphere Commerce Suite 4.0.1 - Unauthenticated Source Code Disclosure via JSP URL Traversal

Title source: llm
STIX 2.1

Description

IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.

References (1)

Core 1
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=98583082225053&w=2

Scores

EPSS 0.0132
EPSS Percentile 68.0%

Details

Status published
Products (1)
ibm/websphere_commerce_suite 4.0.1
Published Jun 18, 2001
Tracked Since Feb 18, 2026