Description
Unknown vulnerability in IBM Websphere Application Server 5.0, 5.1, and 6.0 when running on Windows, allows remote attackers to obtain the source code for Java Server Pages (.jsp) via a crafted URL that causes the page to be processed by the file serving servlet instead of the JSP engine.
References (3)
Core 3
Core References
Patch, Vendor Advisory x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg24008815
Patch, Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/14274
Patch, Vendor Advisory x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg24008814
Scores
EPSS
0.0210
EPSS Percentile
79.7%
Details
Status
published
Products (3)
ibm/websphere_application_server
5.0
ibm/websphere_application_server
5.1.0
ibm/websphere_application_server
6.0
Published
May 02, 2005
Tracked Since
Feb 18, 2026