CVE-2001-0446
IBM WebSphere Commerce Suite 4.0.1 - Unauthenticated Source Code Disclosure via JSP URL Traversal
Title source: llmDescription
IBM WCS (WebSphere Commerce Suite) 4.0.1 with Application Server 3.0.2 allows remote attackers to read source code for .jsp files by appending a / to the requested URL.
References (1)
Core 1
Core References
Mailing List mailing-list
x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=98583082225053&w=2
Scores
EPSS
0.0132
EPSS Percentile
68.0%
Details
Status
published
Products (1)
ibm/websphere_commerce_suite
4.0.1
Published
Jun 18, 2001
Tracked Since
Feb 18, 2026