First published: Thu Jun 08 2000(Updated: )
Unify eWave ServletExec allows a remote attacker to view source code of a JSP program by requesting a URL which provides the JSP extension in upper case.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unify eWave ServletExec | =3.0 | |
Unify eWave ServletExec |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0498 is considered a medium severity vulnerability due to its potential for exploitation by remote attackers.
To fix CVE-2000-0498, configure the web server to restrict access to JSP source files and ensure proper server hardening.
CVE-2000-0498 affects users of Unify eWave ServletExec version 3.0 and potentially other versions of the software.
An attacker can exploit CVE-2000-0498 to view the source code of JSP programs, leading to potential information disclosure.
There is no specific patch for CVE-2000-0498; users should implement security best practices to mitigate the vulnerability.