CVE-2001-0389: Medium severity IBM Net.Commerce vulnerability
Published May 24, 2001
·Updated
IBM Websphere/NetCommerce3 3.1.2 allows remote attackers to determine the real path of the server by directly calling the macro.d2w macro with a NOEXISTINGHTMLBLOCK argument.
Affected Software
2 affected components
IBM Net.Commerce=3.1.2
IBM WebSphere Application Server=5.1.0.3
Event History
May 24, 2001
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-0389?
CVE-2001-0389 is classified as a medium severity vulnerability.
2
How do I fix CVE-2001-0389?
To fix CVE-2001-0389, ensure that the application is updated to a version that does not allow direct calls to the macro.d2w with a NOEXISTINGHTMLBLOCK argument.
3
Who is affected by CVE-2001-0389?
CVE-2001-0389 affects users of IBM Net.Commerce version 3.1.2 and IBM Websphere Application Server version 5.1.0.3.
4
What does CVE-2001-0389 exploit?
CVE-2001-0389 exploits a vulnerability that allows remote attackers to disclose the real path of the server.
5
Can CVE-2001-0389 lead to further attacks?
Yes, the information disclosure from CVE-2001-0389 can potentially lead to further attacks on the vulnerable server.