CVE-2006-7164

IBM WebSphere App Server <5.0.2.7 - Info Disclosure

Title source: llm
STIX 2.1

Description

SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.

References (1)

Core 1
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-1.ibm.com/support/docview.wss?uid=swg24013029

Scores

EPSS 0.0144
EPSS Percentile 70.5%

Details

Status published
Products (18)
ibm/websphere_application_server 5.0.1
ibm/websphere_application_server 5.0.2
ibm/websphere_application_server 5.0.2.1
ibm/websphere_application_server 5.0.2.2
ibm/websphere_application_server 5.0.2.3
ibm/websphere_application_server 5.0.2.4
ibm/websphere_application_server 5.0.2.5
ibm/websphere_application_server 5.0.2.6
ibm/websphere_application_server 5.0.2.7
ibm/websphere_application_server 5.0.2.8
... and 8 more
Published Mar 20, 2007
Tracked Since Feb 18, 2026