← Back
CWE-178

103 CVEs • Abstraction: Base

Improper Handling of Case Sensitivity

The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

JSON object

Loading...

CVEs (103)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Unify
1Ewave Servletexec
Apr 16, 2026
Jun 8, 2000
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
1Ibm
1Websphere Application Server
Apr 16, 2026
Jun 8, 2000
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
1Netscape
1Fasttrack Server
Apr 16, 2026
Jan 1, 1998
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Netscape FastTrack Web server lists files when a lowercase "get" command is used instead of an uppercase GET.