First published: Tue Jan 09 2001(Updated: )
Unify ServletExec AS v3.0C allows remote attackers to read source code for JSP pages via an HTTP request that ends with characters such as ".", or "+", or "%20".
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Unify eWave ServletExec | =3.0c | |
Unify eWave ServletExec | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-1114 is categorized as a medium severity vulnerability.
CVE-2000-1114 allows remote attackers to read the source code of JSP pages, potentially exposing sensitive information.
CVE-2000-1114 affects Unify eWave ServletExec versions 3.0 and 3.0C.
To mitigate CVE-2000-1114, configure the servlet container to restrict access to JSP source files.
There is no specific patch for CVE-2000-1114; users are advised to apply best practices for securing web applications.