← Back

CVE-2006-7164

nvd nist
Published: Mar 20, 2007Modified: Apr 23, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:P/I:N/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

SimpleFileServlet in IBM WebSphere Application Server 5.0.1 through 5.0.2.7 on Linux and UNIX does not block certain invalid URIs and does not issue a security challenge, which allows remote attackers to read secure files and obtain sensitive information via certain requests.

Affected (18)

1 product
Websphere Application Server
Configuration A
18 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Ibm
Version 5.0.1
Version 5.0.2.10
Version 5.0.2.11
Version 5.0.2.12
Version 5.0.2.13
Version 5.0.2.14
Version 5.0.2.15
Version 5.0.2.16
Version 5.0.2.1
Version 5.0.2.2
Version 5.0.2.3
Version 5.0.2.4
Version 5.0.2.5
Version 5.0.2.6
Version 5.0.2.7
Version 5.0.2.8
Version 5.0.2.9
Version 5.0.2
Running on/withPlatform Versions
Linux
Linux Kernel
All versions
Unix
Unix
All versions

References (2)

Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.