← Back

CVE-2010-0777

nvd nist
Published: May 17, 2010Modified: Apr 29, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

The Web Container in IBM WebSphere Application Server (WAS) 6.0 before 6.0.2.43, 6.1 before 6.1.0.31, and 7.0 before 7.0.0.11 does not properly handle long filenames and consequently sends an incorrect file in some responses, which allows remote attackers to obtain sensitive information by reading the retrieved file.

Affected (76)

1 product
Websphere Application Server
Configuration A
51 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 6.0.0.1
Version 6.0.0.2
Version 6.0.0.3
Version 6.0.1.11
Version 6.0.1.13
Version 6.0.1.15
Version 6.0.1.17
Version 6.0.1.1
Version 6.0.1.2
Version 6.0.1.3
Version 6.0.1.5
Version 6.0.1.7
Version 6.0.1.9
Version 6.0.1
Version 6.0.2.10
Version 6.0.2.11
Version 6.0.2.12
Version 6.0.2.13
Version 6.0.2.14
Version 6.0.2.15
Version 6.0.2.16
Version 6.0.2.17
Version 6.0.2.18
Version 6.0.2.19
Version 6.0.2.1
Version 6.0.2.20
Version 6.0.2.21
Version 6.0.2.22
Version 6.0.2.23
Version 6.0.2.24
Version 6.0.2.25
Version 6.0.2.27
Version 6.0.2.28
Version 6.0.2.29
Version 6.0.2.2
Version 6.0.2.30
Version 6.0.2.31
Version 6.0.2.32
Version 6.0.2.33
Version 6.0.2.35
Version 6.0.2.37
Version 6.0.2.39
Version 6.0.2.3
Version 6.0.2.4
Version 6.0.2.5
Version 6.0.2.6
Version 6.0.2.7
Version 6.0.2.8
Version 6.0.2.9
Version 6.0.2
Version 6.0
Configuration B
19 vulnerable
Configuration C
6 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 7.0.0.1
Version 7.0.0.3
Version 7.0.0.5
Version 7.0.0.7
Version 7.0.0.9
Version 7.0

References (12)

Timeline

No history available yet.